CVE-2024-56799
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
30/12/2024
Last modified:
15/04/2026
Description
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL



