Junglewise Threat Intelligence

CVE-2026-55417: Chevereto missing authorization in JSON endpoint bypasses profile privacy

CVE-2026-55417 · Severity: info · CVSS 6.9 · Published 2026-07-07

Executive brief

Chevereto is a self-hosted platform used for hosting and sharing images. A security flaw allows unauthorized individuals to bypass privacy settings intended to hide a user's profile. Even if a user marks their profile as private, an attacker can still view their username and list of public images, potentially leading to privacy violations and unintended data exposure.

Technical details

A missing authorization check (CWE-862) exists in the `/json` AJAX listing endpoint of Chevereto. While the standard HTML profile route (`/username`) correctly enforces the 'private profile' setting by returning a 404 error, the `/json` endpoint does not validate this setting when processing image list requests. An unauthenticated attacker who knows or enumerates a target's user ID can send a POST request to `/json` with `action=list` to retrieve the user's publicly-scoped images and metadata, including the private username. This issue is resolved in version 4.5.4.

Affected products

  • Chevereto chevereto >= 3.7.5, < 4.5.4
  • Chevereto chevereto/chevereto >= 4.0.5, < 4.5.4
  • Chevereto rodber/chevereto-free >= 1.0.0

Timeline

  • 2026-06-12: advisory: GitHub Security Advisory published
  • 2026-07-07: disclosed: NVD publication date

References