Missing Authorization in Kavita - #VU147281
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to modify global CSS themes.
The vulnerability exists due to missing authorization in the theme upload, deletion, and upstream download actions of ThemeController when handling theme management requests. A remote user can upload arbitrary CSS content or delete themes uploaded by other users to modify global CSS themes.
Uploaded theme content is globally listed and can be retrieved without authentication.