GHSA-w3j8-9p3j-3wjx
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
The project was archived as of December 1, 2023.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-67165, https://github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-67165, https://github.com/pagekit/docs/blob/develop/user-interface/users.md#permissions, https://github.com/pagekit/docs/blob/develop/user-interface/users.md#roles, https://github.com/pagekit/pagekit
