Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 27 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Manyfold
Manyfold manyfold |
|
| CPEs | cpe:2.3:a:manyfold:manyfold:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Manyfold
Manyfold manyfold |
Fri, 27 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Manyfold3d
Manyfold3d manyfold |
|
| Vendors & Products |
Manyfold3d
Manyfold3d manyfold |
Thu, 26 Feb 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.1, the `get_model` method in `ModelFilesController` (line 158-160) loads models using `Model.find_param(params[:model_id])` without `policy_scope()`, bypassing Pundit authorization. All other controllers correctly use `policy_scope(Model).find_param()` (e.g., `ModelsController` line 263). Version 0.133.1 fixes the issue. | |
| Title | Manyfold has IDOR in ModelFilesController | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-27T18:33:16.833Z
Reserved: 2026-02-25T15:28:40.650Z
Link: CVE-2026-28225
Updated: 2026-02-27T18:33:11.636Z
Status : Analyzed
Published: 2026-02-26T23:16:36.413
Modified: 2026-02-27T16:55:07.943
Link: CVE-2026-28225
No data.
OpenCVE Enrichment
Updated: 2026-04-16T16:00:13Z