{"id":"CVE-2026-77165","published":"2026-09-21T16:17:23.863","lastModified":"2026-09-21T19:17:10.713","description":"File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://hackerone.com/reports/3770482","tags":[]},{"url":"https://hackerone.com/reports/3770482","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"Users could not unlock locks placed by other users, potentially leading to data loss or unavailability.","exploitability":"Exploitation requires specific user permissions and locked files; difficult but feasible under certain conditions.","blast_radius":"Impact is limited to the affected files and users, but permanent data loss could occur if not addressed.","remediation":"Ensure all file owners have proper unlock permissions or implement a recovery mechanism for locked files.","tags":["auth-bypass","data-loss","permissions"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:19:17.602Z"}}