CVE-2025-54461: Neojapan Inc Chatluck
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guest user may register itself as a guest user.
Affected products
- Neojapan Inc Chatluck: up to and including V6.6 R2.0
Published 2025-10-16. Last modified 2026-10-09.