Description
archivy is vulnerable to Cross-Site Request Forgery (CSRF)
References (2)
Core 2
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/e204a768-2129-4b6f-abad-e436309c7c32
Patch, Third Party Advisory x_refsource_misc
https://github.com/archivy/archivy/commit/796c3ae318eea183fc88c87ec5a27355b0f6a99d
Scores
CVSS v3
4.3
EPSS
0.0038
EPSS Percentile
29.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-352
Status
published
Products (2)
archivy_project/archivy
< 1.6.1
pypi/archivy
0 - 1.6.2PyPI
Published
Dec 25, 2021
Tracked Since
Feb 18, 2026