Hytale Modding Wiki Insecure Direct Object Reference Vulnerability Allowing Personal Information Exposure

Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability has been identified in the Hytale Modding Wiki, affecting versions prior to 1.0.0. This vulnerability allows any authenticated user to access mod authors' personal information, including full names and email addresses, by simply navigating to a mod's page via its slug. The issue arises because the API response for mod pages includes the complete author object with sensitive personally identifiable information (PII) without proper access control, exposing this data to users who should not have access.

Impact

Exploitation of this vulnerability leads to unauthorized disclosure of personal information, specifically full names and email addresses of mod authors, to any authenticated user on the platform.

Reproduction

To reproduce this vulnerability, create an account on the Hytale Modding Wiki and log in. Then, navigate to any mod page using its slug. After the page loads, inspect the API response for the page request in the browser's Developer Tools. The response will contain the author's full name and email address, which should not be accessible to the user.

Remediation

Users can update to Hytale Modding Wiki version 1.0.0 or later, where this vulnerability has been fixed.

Added: Mar 18, 2026, 11:20 PM
Updated: Mar 18, 2026, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
4.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.