{"id":"CVE-2022-1810","aliases":["BIT-publify-2022-1810","GHSA-c273-c6vg-4pv5"],"url":"https://o3.security/vulnerability/CVE-2022-1810","summary":"Authorization Bypass Through User-Controlled Key in publify/publify","details":"Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.","published":"2022-05-23T00:00:00Z","modified":"2026-08-12T03:51:34.584478146Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H"},"epss":{"score":0.00827,"percentile":0.55305,"asOf":"2026-09-10"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"publify_core","fixedVersion":"9.2.9"}],"fix":{"url":"https://github.com/publify/publify/commit/c0aba87844d1e47da50c0d99a3465164a4d244ce","label":"publify/publify@c0aba87"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/9b2d7579-032e-42da-b736-4b10a868eacb"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1810.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1810"},{"type":"FIX","url":"https://github.com/publify/publify/commit/c0aba87844d1e47da50c0d99a3465164a4d244ce"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.584478146Z"}}