Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their profile HTML route (`/username`) correctly returns 404. However, the `/json` AJAX listing endpoint does not apply the same check. An unauthenticated caller who knows the target's user ID can retrieve all of that user's publicly-scoped images, revealing the username (which should be private). This is patched in Chevereto v4.5.4. No known workarounds are available.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-07 21:17
Updated : 2026-07-10 17:56
NVD link : CVE-2026-55417
Mitre link : CVE-2026-55417
CVE.ORG link : CVE-2026-55417
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
