CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-107450: Stump 0 through 0.1.10

CVE-2026-107450. CVSS 3.1 base score 5.4 (MEDIUM, Vendor/CNA).

Affected technology

Stump · 0 through 0.1.10
stumpapp

Description’s affected range: through 0.1.10

Component: GraphQL smart list mutations
Function: update_smart_list, delete_smart_list
File: crates/graphql/src/mutation/smart_lists.rs

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Any authenticated user with that permission can overwrite, delete, or take over another user's smart list. (updateSmartList sets creatorId to the caller identity, and can set visibility to PRIVATE, locking out the original owner.) NOTE: this is unrelated to the graphql crate on crates.io. Vendor/CNA’s CVSS 3.1 assessment (base score 5.4/10) rates confidentiality impact as none; integrity and availability impact as low.

Published

CWE
CWE-863
CCR priority
21.6 /100 (P4)
CVSS 3.1
5.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107450.html