PatchSiren

opensource-socialnetwork CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH opensource-socialnetwork CVE published 2026-10-10

CVE-2026-108164

CVE-2026-108164 is an insecure direct object reference vulnerability in Open Source Social Network (OSSN) through version 10.1. Authenticated users can read other users' private message attachments by requesting the /messages/attachment/{guid} route with sequential or guessed file GUIDs, without sender or recipient verification. This vulnerability allows attackers to access private conversations, potentia [truncated]