VDB
Sign up
HIGH8.6

PYSEC-2026-1494

Kinto Attachment's attachments can be replaced on read-only records

Quick fix

PYSEC-2026-1494 — kinto-attachment: upgrade to the fixed version with the command below.

pip install --upgrade 'kinto-attachment>=6.4.0'

Details

### Impact

The attachment file of an existing record can be replaced if the user has `"read"` permission on one of the parent (collection or bucket).

And if the `"read"` permission is given to `"system.Everyone"` on one of the parent, then the attachment can be replaced on a record using an anonymous request.

Note that if the parent has no explicit read permission, then the records attachments are safe.

### Patches

- Patch released in kinto-attachment 6.4.0 - https://github.com/Kinto/kinto-attachment/commit/f4a31484f5925cbc02b59ebd37554538ab826ca1

### Workarounds

None if the read permission has to remain granted.

Updating to 6.4.0 or applying the patch individually (if updating is not feasible) is strongly recommended.

### References

- https://bugzilla.mozilla.org/show_bug.cgi?id=1879034

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/kinto-attachment
Introduced in: 0Fixed in: 6.4.0
Fixpip install --upgrade 'kinto-attachment>=6.4.0'

References