rowboatlabs rowboat Session route.ts PUT missing authentication

CVE Details

Basic Information

Title rowboatlabs rowboat Session route.ts PUT missing authentication
Type cve
Published 2025-07-07T06:02:07.544Z
Modified 2025-07-07T06:02:07.544Z

Product Information

Vendor rowboatlabs
Product rowboat
Version 8096eaf63b5a0732edd8f812bee05b78e214ee97

CVSS Information

Base Score 6.9 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

AI Analysis

AI Description A critical vulnerability in rowboatlabs rowboat allows remote attackers to exploit missing authentication in the Session Handler’s PUT function, potentially leading to unauthorized access and data manipulation.
AI Severity High
AI Vendor rowboatlabs
AI Product rowboat
AI Version Commit hash: 8096eaf63b5a0732edd8f812bee05b78e214ee97 (No specific versions available)

Affected Products

  • rowboatlabs rowboat 8096eaf63b5a0732edd8f812bee05b78e214ee97

Additional Information

CWE List CWE-306, CWE-287
Source VulDB

Description

A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issue is the function PUT of the file apps/rowboat/app/api/uploads/[fileId]/route.ts of the component Session Handler. The manipulation of the argument params leads to missing authentication. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. It is expected that this issue will be fixed in the near future.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.