CyberRota Analysis
AI-GeneratedAn authorization bypass vulnerability exists in versions prior to 0.30.0, allowing attackers with read-restricted sessions to exploit the code.replace function to modify permission configurations. This can lead to unauthorized privilege escalation, potentially compromising sensitive operations. Organizations using affected versions should prioritize immediate updates to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.