CVE-2024-56799

CRITICAL

TrueWinter simofa < 0.2.7 - Unauthenticated Access to Restricted API Routes

Title source: llm
STIX 2.1

Description

Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.

Scores

CVSS v3 10.0
EPSS 0.0052
EPSS Percentile 40.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
TrueWinter/simofa < 0.2.7
Published Dec 30, 2024
Tracked Since Feb 18, 2026