Missing Authorization in Kavita - #VU147283
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose age-restricted item metadata.
The vulnerability exists due to missing authorization in the reading-list item repository query when retrieving items from a reading list. A remote user can request a reading list identifier to disclose metadata for content above the user's configured age rating.
Only metadata for series in a library accessible to the user is exposed; chapter reading and downloads remain subject to separate access controls.