CVE-2026-51879: DeepTutor vulnerability
deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.writebotfile. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is reachable by a remote caller through the HTTP tutorbot file route. The provided data does not state that authentication or any special privileges are required.
What can an attacker change if exploitation succeeds?
An attacker who can enumerate bot IDs can overwrite whitelisted control files belonging to another bot via TutorBotManager.write_bot_file.
How can I determine whether my deployment is affected?
The affected version identified in the provided data is deeptutor 1.4.0. Review whether the HTTP tutorbot file route is exposed and whether callers can supply bot identifiers used by TutorBotManager.write_bot_file.