CRITICAL
CVE-2026-57578
CVSS
9.2
Description
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewModelActionFilter.OnViewModelCreatedAsync, and IPresenterActionFilter.OnPresenterExecutingAsync implementations return completed tasks instead of invoking the corresponding checks. Applications relying on this filter can therefore expose protected commands, view models, or presenters to unauthorized requests without any special bypass technique. AuthorizeAttribute correctly implements the same interfaces and can be used as a workaround. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.44%
Probability of exploitation in next 30 days
37.6th percentile
References
https://github.com/riganti/dotvvm/commit/1635245b5eaf9ccf8e3536b9d8b1941819526585
https://github.com/riganti/dotvvm/commit/4fc26a8591c76fb92ed701352c2a84120cf926c5
https://github.com/riganti/dotvvm/commit/7578cf3459097cbbef0d3fea8a7774509b324112
https://github.com/riganti/dotvvm/releases/tag/v4.3.15
https://github.com/riganti/dotvvm/releases/tag/v5.0.0-preview09
https://github.com/riganti/dotvvm/security/advisories/GHSA-c8qj-jx8j-fg2w
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.