CVE-2019-16281: Ptarmigan Project Ptarmigan
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code block.
Affected products
- Ptarmigan Project Ptarmigan: before 0.2.3 (fixed in 0.2.3)
Published 2020-12-30. Last modified 2026-06-17.