


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST API Endpoin…
Published:
25 april 2026 om 22:00:00
Alert date:
26 april 2026 om 23:04:07
Source:
nvd.nist.gov
Web Technologies
A critical authentication bypass vulnerability has been discovered in 666ghj MiroFish versions up to 0.1.2. The flaw affects the create_app function in the REST API endpoint, allowing remote attackers to bypass authentication mechanisms. The vulnerability can be exploited remotely and a public exploit is available. The issue was reported to the project maintainers but they have not yet responded to address the security concern.
Technical details
Mitigation steps:
Affected products:
MiroFish
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7042
https://github.com/666ghj/MiroFish/
https://github.com/666ghj/MiroFish/issues/487
https://vuldb.com/submit/798583
https://vuldb.com/vuln/359621
https://vuldb.com/vuln/359621/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
