Executive brief
An authorization bypass vulnerability exists in the Ribblr iOS application, a platform used for buying, selling, and managing crochet and knitting patterns. A logged-in user can potentially access or manipulate data they are not authorized to see by modifying identifiers in their requests. This could lead to unauthorized access to other users' patterns or account information.
Technical details
The Ribblr iOS application is vulnerable to an authorization bypass classified as CWE-639 (Authorization Bypass Through User-Controlled Key). An authenticated attacker can exploit this by manipulating user-controlled keys or identifiers in network requests to access resources belonging to other users. The vulnerability is reachable over the network and requires a low-privileged authenticated account. Successful exploitation allows the attacker to bypass intended access controls, though the impact is limited to low confidentiality loss (VC:L) according to the CVSS 4.0 assessment.
Affected products
- Ribblr Ribblr - Crochet & Knitting iOS application
Timeline
- 2026-04-27: disclosed: Initial disclosure by National Cyber Security Centre Finland
- 2026-04-27: advisory: NVD publication date