What is CVE-2026-45377?
CVE-2026-45377 is a vulnerability in the Decidim participatory democracy framework where the Active Storage blob redirect URL from the 'download_your_data' function can be replayed without authentication. It affects versions prior to 0.30.9, 0.31.0 before 0.31.5, and 0.32.0.rc1, potentially leading to unauthorized data access. Users should upgrade to versions 0.30.9, 0.31.5, or 0.32.0.rc2 immediately.
Azərbaycanca: CVE-2026-45377 Decidim platformasında aşkarlanmış zəiflikdir ki, bu, "download_your_data" funksiyasında Active Storage blob yönləndirmə URL-nin təkrar istifadəsinə imkan verir. Problem 0.30.9-dan əvvəlki, 0.31.0-0.31.5 arası və 0.32.0.rc1 versiyalarına təsir edir, şəxsi məlumatların icazəsiz əldə olunmasına səbəb ola bilər. İstifadəçilərə dərhal 0.30.9, 0.31.5 və ya 0.32.0.rc2 versiyalarına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which function is exploited in CVE-2026-45377?
The vulnerability can be exploited through the Active Storage blob redirect URL in the "download_your_data" function of the Decidim platform.
Which versions should be upgraded to in order to mitigate CVE-2026-45377?
Users are advised to upgrade to versions 0.30.9, 0.31.5, or 0.32.0.rc2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.