—
PYSEC-2026-1193
askbot inexhaustive permissions check allows any user to modify a different user's profile picture
Quick fix
PYSEC-2026-1193 — askbot: upgrade to the fixed version with the command below.
pip install --upgrade 'askbot>=0.12.3'Details
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users. This issue affects askbot: 0.12.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-1213[ADVISORY]
- https://github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cb6295d[WEB]
- https://askbot.com[WEB]
- https://fluidattacks.com/advisories/ghost[WEB]
- https://github.com/askbot/askbot-devel[PACKAGE]
- https://pypi.org/project/askbot[PACKAGE]
- https://github.com/advisories/GHSA-r2jv-fwfr-4j8c[ADVISORY]