CVE-2025-15550: Birkir Prime

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows attackers to exploit GET-based query requests. Attackers can craft malicious GET requests to trigger unauthorized actions against privileged users by manipulating GraphQL query parameters.

Affected products

  • Birkir Prime: up to and including 0.4.0.beta.0

Published 2026-01-29. Last modified 2026-06-17.