{"id":"CVE-2026-71518","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71518","summary":"Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting…","details":"Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.","published":"2026-08-17T21:16:48.277","modified":"2026-08-17T21:16:48.277","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/typemill/typemill/commit/8c621063b4697a94342cb0a4b3905adda60e3d25","label":"typemill/typemill@8c62106"},"references":[{"type":"WEB","url":"https://github.com/typemill/typemill/commit/8c621063b4697a94342cb0a4b3905adda60e3d25"},{"type":"WEB","url":"https://github.com/typemill/typemill/releases/tag/v2.26.0"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/typemill-authorization-bypass-via-media-file-download-route"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T21:16:48.277"}}