
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1213 is an authorization bypass vulnerability in askbot, an open-source Q&A forum application, that allows any authenticated user with normal permissions to modify the profile picture of other users. All versions up to and including 0.12.2 are affected; the issue was fixed in version 0.12.3. It was discovered and disclosed on January 27, 2026, with a GitHub Security Advisory (GHSA-r2jv-fwfr-4j8c) published the same day. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Feedly).
The root cause is an improper authorization check in the admin_or_owner_required decorator within askbot/views/avatar_views.py, classified as CWE-639 (Authorization Bypass Through User-Controlled Key). The vulnerable code compared the authenticated user's integer id directly against the user_id URL parameter, which Django passes as a string — causing the equality check (request.user.id == user_id) to always evaluate to False for non-admin users, effectively bypassing ownership validation for all requests. An attacker only needs a valid authenticated session and knowledge of another user's numeric ID (which is typically enumerable from public profile URLs) to exploit this flaw by sending a crafted HTTP request to the avatar modification endpoint with a different user's ID in the URL (GitHub Commit, GitHub Advisory).
Successful exploitation allows an authenticated attacker to replace the profile picture of any other user in the application without authorization. The primary impact is to integrity — an attacker can impersonate other users visually, cause reputational damage, or disrupt trust within the community platform. There is no confidentiality or availability impact, and the vulnerability does not enable lateral movement or privilege escalation beyond profile picture modification (GitHub Advisory, Feedly).
A proof-of-concept exploit is publicly available via Fluid Attacks' advisory at https://fluidattacks.com/advisories/ghost, which is the original reporting source for this vulnerability. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.011% (2nd percentile), indicating a low probability of near-term exploitation (GitHub Advisory, Feedly).
/users/42/username/)./account/upload-avatar/ or a similar URL handled by the avatar_views.py module.request.user.id (integer) to the URL-supplied user_id (string), the check always failed, granting access./account/upload-avatar/) where the user_id URL parameter does not match the authenticated session's user ID.Upgrade askbot to version 0.12.3 or later, which includes the security fix committed in commit 3da3d75. The fix corrects the type mismatch by explicitly converting the URL-supplied user_id string to an integer before comparison in the admin_or_owner_required decorator. If immediate patching is not possible, consider temporarily disabling profile picture upload functionality or implementing a web application firewall rule to block avatar modification requests where the session user ID does not match the URL parameter (GitHub Advisory, GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."