Executive brief
JFrog Artifactory is a software repository manager that stores and distributes code packages. Under specific circumstances, a low-privileged user can trigger requests to remote CocoaPods repositories (a package manager for Apple development), potentially allowing unauthorized access to external repository information that they should not be able to reach.
Technical details
This vulnerability exists in JFrog Artifactory's handling of external dependencies for CocoaPods repositories. A low-privileged authenticated user can craft requests that are forwarded to remote CocoaPods repositories without proper authorization validation, allowing them to interact with external package sources they are not entitled to access. The vulnerability requires specific configuration conditions and an authenticated user account to exploit. Patches are available in Artifactory versions 7.161.17+, 7.146.30+, and newer release branches.
Affected products
- JFrog Artifactory 7.161.0–7.161.1, 7.161.11–7.161.16, 7.146.0–7.146.29
Timeline
- 2026-08-25: disclosed
- 2026-08-25: advisory