HIGH
opensource-socialnetwork
CVE published 2026-10-10
CVE-2026-108164
CVE-2026-108164 is an insecure direct object reference vulnerability in Open Source Social Network (OSSN) through version 10.1. Authenticated users can read other users' private message attachments by requesting the /messages/attachment/{guid} route with sequential or guessed file GUIDs, without sender or recipient verification. This vulnerability allows attackers to access private conversations, potentia [truncated]