CVE-2026-108164: Opensource-Socialnetwork
Medium severity, CVSS 6.5.
Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that allows authenticated users to read other users' private message attachments. Attackers can request the /messages/attachment/{guid} route with sequential or guessed file GUIDs to retrieve attachments from private conversations without sender or recipient verification.
Affected products
- Opensource-Socialnetwork Opensource-Socialnetwork: up to and including 10.1
Published 2026-10-10. Last modified 2026-10-10.