Junglewise Threat Intelligence

CVE-2026-13591: DeepMyst Mysti improper authorization in ChannelBridge

CVE-2026-13591 · Severity: medium · CVSS 5 · Published 2026-06-29

Executive brief

DeepMyst Mysti, an AI-driven coding assistant for VS Code, contains a security flaw in how it tracks communication channels. An attacker could potentially spoof a sender's identity across different communication channels, leading to unauthorized message routing. This could allow a malicious actor to impersonate legitimate users or interfere with the AI's collaborative coding sessions.

Technical details

An improper authorization vulnerability exists in the `_isTrackedConversation` function within `src/managers/ChannelBridge.ts` of DeepMyst Mysti 0.4.0. The root cause is insufficient scoping of contact tracking, which relies on a generic `_channelType` argument rather than a unique channel identifier. A remote attacker with low privileges can exploit this logic flaw to perform cross-channel identity spoofing or inbound message routing confusion. While the attack requires high complexity and specific preconditions to successfully match pending requests, a public exploit is available. The issue is resolved in patch `9b4aff0f106db424aa45a35aa89dd0b8f2eb9a48` by implementing exact OpenClaw channel ID scoping.

Affected products

  • DeepMyst Mysti 0.4.0

Timeline

  • 2026-06-01: disclosed: Issue reported on GitHub
  • 2026-06-12: patched: Fix committed to repository
  • 2026-06-29: advisory: CVE published to NVD

References

Related threats