Executive brief
Kavita is a digital library server used for hosting and reading books and comics. A critical security flaw allows an unauthorized person to take over any user account, including administrator accounts, simply by knowing their username. This could lead to a total loss of privacy for readers and full control over the server's content and settings.
Technical details
An improper authentication vulnerability exists in Kavita due to flawed token validation logic. The root cause involves insufficient verification of data authenticity and incorrect comparisons during the authentication process (CWE-287, CWE-345, CWE-697). A remote, unauthenticated attacker can exploit this by requesting a JSON Web Token (JWT) for any valid username, including administrative accounts. Successful exploitation results in complete account takeover and full access to the application's API and management features. The vulnerability is addressed in version 0.9.0.2.
Affected products
- Kareadita Kavita < 0.9.0.2
Timeline
- 2026-05-14: patched: Version 0.9.0.2 released as a security hotfix.
- 2026-05-19: advisory: GitHub Security Advisory GHSA-m2v3-fcjh-hm22 published.
- 2026-05-26: disclosed: CVE-2026-47202 published to the NVD.