CVE-2024-52872: Flagsmith

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

Affected products

  • Flagsmith Flagsmith: before 2.134.1 (fixed in 2.134.1)

Published 2024-11-17. Last modified 2026-06-17.