CVE-2026-65319
HIGHFeedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text
Title source: cnaDescription
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and extract plain-text content of all stored articles, including private newsletter content, personal page-saves, and articles from any user's private subscriptions.
References (4)
Core 4
Core References
Patch product
patch
Patch Commit
https://github.com/feedbin/feedbin/commit/04b89b84189e4727ea19d84ea4a44015859b29cc
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/feedbin-unauthenticated-entry-content-disclosure-via-get-api-v2-entries-id-text
Scores
CVSS v3
7.5
EPSS
0.0037
EPSS Percentile
29.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
Feedbin/Feedbin
< 739884a
Published
Jul 21, 2026
Tracked Since
Jul 22, 2026