CVE-2024-56799: Truewinter Simofa
Critical severity, CVSS 10.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.
Affected products
- Truewinter Simofa: before 0.2.7 (fixed in 0.2.7)
Published 2024-12-30. Last modified 2026-06-17.