Venueless API User Account Deletion Vulnerability

Vulnerability

A vulnerability exists in the Venueless API that allows users with 'manage users' permissions to delete user accounts in other worlds. This issue affects all versions prior to the commit 02b9cbe5.

Impact

Exploitation of this vulnerability leads to unauthorized deletion of user accounts in different worlds, causing potential loss of user data and disruption of user activities.

Remediation

The vulnerability has been patched in all commits after 02b9cbe5. Users should avoid granting privileged permissions to individuals.

Added: Apr 5, 2026, 1:19 PM
Updated: Apr 5, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
5.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.