CVE-2026-86113: BookWyrm through 0.9.1 Insecure Direct Object Reference in edit-readthrough Allows Tampering with Other Users' Reading Records
BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the editreadthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated BookWyrm user can exploit it. No user interaction is required, and the attacker can target other users' reading records by using ReadThrough IDs.
Which data can an attacker change?
An attacker can overwrite another user's start date, finish date, progress, and progress mode. This can alter reading statistics and exported data.
Are unauthenticated users affected?
The available information identifies this as an authenticated authorization bypass. It does not indicate that unauthenticated users can exploit it.
Which versions are known to be affected?
BookWyrm through version 0.9.1 is identified as affected.