PYSEC-2026-1494
Kinto Attachment's attachments can be replaced on read-only records
Quick fix
PYSEC-2026-1494 — kinto-attachment: upgrade to the fixed version with the command below.
pip install --upgrade 'kinto-attachment>=6.4.0'Details
### Impact
The attachment file of an existing record can be replaced if the user has `"read"` permission on one of the parent (collection or bucket).
And if the `"read"` permission is given to `"system.Everyone"` on one of the parent, then the attachment can be replaced on a record using an anonymous request.
Note that if the parent has no explicit read permission, then the records attachments are safe.
### Patches
- Patch released in kinto-attachment 6.4.0 - https://github.com/Kinto/kinto-attachment/commit/f4a31484f5925cbc02b59ebd37554538ab826ca1
### Workarounds
None if the read permission has to remain granted.
Updating to 6.4.0 or applying the patch individually (if updating is not feasible) is strongly recommended.
### References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1879034
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 6.4.0pip install --upgrade 'kinto-attachment>=6.4.0'References
- https://github.com/Kinto/kinto-attachment/security/advisories/GHSA-hvp4-vrv2-8wrq[WEB]
- https://github.com/Kinto/kinto-attachment/commit/f4a31484f5925cbc02b59ebd37554538ab826ca1[FIX]
- https://bugzilla.mozilla.org/show_bug.cgi?id=1879034[WEB]
- https://github.com/Kinto/kinto-attachment[PACKAGE]
- https://pypi.org/project/kinto-attachment[PACKAGE]
- https://github.com/advisories/GHSA-hvp4-vrv2-8wrq[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-1314[ADVISORY]