[CVE-2026-19965] A vulnerability was determined in automad up to 2.0.0-beta.3

CVE-2026-19965 | CVSS: 3.7 | 严重级别: LOW

A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b

参考链接:
https://github.com/marcantondahmen/automad/commit/eac0b05dafdb0ddf8b9139dad8929a
https://github.com/marcantondahmen/automad/issues/191
https://github.com/marcantondahmen/automad/releases/tag/2.0.0-beta.33

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部