Get real-time updates on Telegram
CVE-2026-107450: Stump 0 through 0.1.10
CVE-2026-107450. CVSS 3.1 base score 5.4 (MEDIUM, Vendor/CNA).
Affected technology
Stump · 0 through 0.1.10
stumpapp
Description’s affected range: through 0.1.10
Component: GraphQL smart list mutations
Function: update_smart_list, delete_smart_list
File: crates/graphql/src/mutation/smart_lists.rs
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Any authenticated user with that permission can overwrite, delete, or take over another user's smart list. (updateSmartList sets creatorId to the caller identity, and can set visibility to PRIVATE, locking out the original owner.) NOTE: this is unrelated to the graphql crate on crates.io. Vendor/CNA’s CVSS 3.1 assessment (base score 5.4/10) rates confidentiality impact as none; integrity and availability impact as low.
- CWE
- CWE-863
- CCR priority
- 21.6 /100 (P4)
- CVSS 3.1
- 5.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L · Vendor/CNA
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107450.html