CVE-2026-71518: Typemill < 2.26.0 Authorization Bypass via Media File Download Route
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Typemillto a version that resolves this vulnerability.Fixed in 2.26.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71518?
The severity of CVE-2026-71518 is rated high with a CVSS score of 7.5.
What is the impact of CVE-2026-71518?
CVE-2026-71518 allows unauthenticated attackers to access restricted files through an authorization bypass in the media file download route.
How do I fix CVE-2026-71518?
To fix CVE-2026-71518, upgrade Typemill to version 2.26.0 or later.
Who is affected by CVE-2026-71518?
Typemill versions prior to 2.26.0 are affected by CVE-2026-71518.
What type of vulnerability is CVE-2026-71518?
CVE-2026-71518 is an authorization bypass vulnerability.