Authorization bypass through user-controlled key in Kavita - #VU147284
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose file sizes of series, volumes, and chapters in restricted libraries.
The vulnerability exists due to authorization bypass through user-controlled key in the `bulk-volume-size`, `bulk-chapter-size`, and `bulk-series-size` endpoints when processing POST requests containing user-supplied entity ID arrays. A remote user can submit arbitrary series, volume, or chapter IDs to disclose file sizes of restricted entities.
The account must have the Download role.