Junglewise Threat Intelligence

CVE-2025-15626: Ribblr iOS App Authorization Bypass via User-Controlled Key

CVE-2025-15626 · Severity: info · CVSS 5.3 · Published 2026-04-27

Executive brief

An authorization bypass vulnerability exists in the Ribblr iOS application, a platform used for buying, selling, and managing crochet and knitting patterns. A logged-in user can potentially access or manipulate data they are not authorized to see by modifying identifiers in their requests. This could lead to unauthorized access to other users' patterns or account information.

Technical details

The Ribblr iOS application is vulnerable to an authorization bypass classified as CWE-639 (Authorization Bypass Through User-Controlled Key). An authenticated attacker can exploit this by manipulating user-controlled keys or identifiers in network requests to access resources belonging to other users. The vulnerability is reachable over the network and requires a low-privileged authenticated account. Successful exploitation allows the attacker to bypass intended access controls, though the impact is limited to low confidentiality loss (VC:L) according to the CVSS 4.0 assessment.

Affected products

  • Ribblr Ribblr - Crochet & Knitting iOS application

Timeline

  • 2026-04-27: disclosed: Initial disclosure by National Cyber Security Centre Finland
  • 2026-04-27: advisory: NVD publication date

References