← Vulnerability feed

Vulnerability record · CVE-2022-34621 · published 19 August 2022

CVE-2022-34621: Mealie insecure direct object reference vulnerability

Mealie · Mealie

Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.

6.5 CVSS 3.1 Medium EPSS 1.0% · top 37.8% CWE-639 · Insecure direct object reference
6.5CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-34621 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34615Mealie weak password requirements vulnerabilityMealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-forc…EPSS 1.5%9.0CVE-2025-56795Mealie cross-site scripting vulnerabilityMealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note…EPSS 0.36%7.6CVE-2024-55073Mealie missing authorization vulnerabilityA Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profi…EPSS 0.30%6.5CVE-2024-31994Mealie uncontrolled resource consumption vulnerabilityMealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. Mealie…EPSS 0.28%6.5CVE-2024-31992Mealie uncontrolled resource consumption vulnerabilityMealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a requ…EPSS 0.72%6.1CVE-2025-70297Mealie cross-site scripting vulnerabilityA stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated …EPSS 0.19%5.9CVE-2022-34624Mealie insufficient session expiration vulnerabilityMealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET…EPSS 0.61%5.4CVE-2025-70296Mealie command injection vulnerabilityA stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary H…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2022-34621), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.