CVE-2026-4171
Last modified
CVE-2026-4171 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4171?
How severe is CVE-2026-4171?
How do I fix CVE-2026-4171?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-41703VMware ESX, Workstation, and Fusion contain an out-of-bounds…7.6
- CVE-2026-41704AgentClient#handle_method (lines 264-303) processes every NA…6.8
- CVE-2026-41705Spring AI's MilvusVectorStore#doDelete(List) implementation …8.6
- CVE-2026-41706Spring Security's CookieRequestCache and CookieServerRequest…6.1
- CVE-2026-41708In Spring Cloud Sleuth, it is possible for a user to provide…7.5
- CVE-2026-41709VMware ESX contains an insufficient logging vulnerability. A…2.7
- CVE-2026-41710An attacker can craft a large number of unique requests that…5.9
- CVE-2026-41711Applications using Spring Data Commons may be vulnerable to …5.9
- CVE-2026-41712Spring AI's chat memory component contained a problematic de…7.5
- CVE-2026-41713A malicious user could craft input that is stored in convers…8.2
- CVE-2026-41714Applications that configure their broker connection via Rabb…4
- CVE-2026-41715In specific scenarios involving HTTP redirects from a secure…6.1
Are you affected by CVE-2026-4171?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
