HIGH
CVE-2026-36453
CVSS
7.4
Description
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
Weakness (CWE)
CWE-425
EPSS Score
0.16%
Probability of exploitation in next 30 days
5.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.