216.73.217.22

CVE-2026-7142

· Published 27/04/2026 17:16 · Modified 27/04/2026 18:35

Labels: CVE-2026-7142 2026-04-27CVE-2026-7142CWE-266[email protected]

Essential information

Published
27/04/2026 17:16
Modified
27/04/2026 18:35
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of the component API Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.13.3rc1 and 0.14.0 is sufficient to resolve this issue. This patch is called f7846fc0c323da8325422cab32623491757f1b88. The affected component should be upgraded.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wooey / wooey cpe:2.3:a:wooey:wooey:0.13.2:*:*:*:*:*:*:*
wooey / wooey cpe:2.3:a:wooey:wooey:0.13.3rc1:*:*:*:*:*:*:*
wooey / wooey cpe:2.3:a:wooey:wooey:0.14.0:*:*:*:*:*:*:*

References