PatchSiren

bookwyrm-social CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH bookwyrm-social CVE published 2026-09-05

CVE-2026-86113

CVE-2026-86113 is an authorization bypass vulnerability in BookWyrm through version 0.9.1. This vulnerability allows authenticated users to modify other users' reading records by exploiting sequential ReadThrough IDs, potentially affecting reading statistics and exported data. The edit_readthrough function is specifically impacted, and defenders should assess exposure and prioritize verification of user a [truncated]