Grimmory Tools Grimmory
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Grimmory Tools Grimmory.
By the Year
In 2026 there have been 2 vulnerabilities in Grimmory Tools Grimmory with an average score of 5.3 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 5.30 |
It may take a day or so for new Grimmory vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Grimmory Tools Grimmory Security Vulnerabilities
Auth Bypass in Grimmory-Tools 3.3.3 Download Endpoint via bookId
CVE-2026-93955
5.3 - Medium
- September 19, 2026
A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. Issue #2431 is closed as completed, but its only comment states that the issue has already been reported elsewhere. No fixing commit or pull request is identified there.
Insecure Direct Object Reference / IDOR
AUC: Incorrect Auth via Settings API Endpoint in Grimmory <3.4.1 (Java)
CVE-2026-93954
5.3 - Medium
- September 19, 2026
A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.
AuthZ
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Grimmory Tools Grimmory or by Grimmory Tools? Click the Watch button to subscribe.