Junglewise Threat Intelligence

CVE-2026-35173: Chyrp Lite IDOR and Mass Assignment in Post model

CVE-2026-35173 · Severity: medium · CVSS 6.5 · Published 2026-04-06

Executive brief

Chyrp Lite is a lightweight blogging platform. A security flaw allows users with basic post-editing permissions to modify or take over blog posts created by other users. This could lead to unauthorized content changes or the hijacking of posts on a website, potentially damaging the site's reputation or spreading misinformation.

Technical details

An Insecure Direct Object Reference (IDOR) and Mass Assignment vulnerability exists in the Post model of Chyrp Lite. The root cause is located in 'includes/model/Post.php', where the '__construct()' method (via 'Model::grab') assigns attributes from the 'post_attributes' database table directly to the object instance without proper filtering. An authenticated attacker with post-editing permissions can inject internal class properties, such as 'id', into the 'post_attributes' payload. This 'poisons' the object, causing the application to perform subsequent update actions on a different post ID than intended. This allows for unauthorized modification and takeover of posts belonging to other users. The issue is fixed in version 2026.01 by preventing the overwriting of already-set class properties.

Affected products

  • xenocrat Chyrp Lite < 2026.01

Timeline

  • 2026-03-14: advisory: Vendor advisory published on GitHub
  • 2026-04-06: disclosed: CVE published to NVD
  • 2026-01: patched: Vulnerability fixed in version 2026.01

References

Related threats