CVE-2026-13591 Details
Description
A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of the component Contact Tracking. This manipulation of the argument _channelType causes improper authorization. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. Patch name: 9b4aff0f106db424aa45a35aa89dd0b8f2eb9a48. It is suggested to install a patch to address this issue.
A vulnerability exists in DeepMyst Mysti version 0.4.0 within the Contact Tracking function of the ChannelBridge manager. The issue arises from the manipulation of the _channelType argument, leading to improper authorization. This vulnerability allows cross-channel sender spoofing by misusing the contact tracking system, which can be exploited remotely with a high level of complexity. The flaw has been publicly disclosed and is associated with a patch that is available.
A patch is available for this vulnerability. Users are advised to update to the latest version of DeepMyst Mysti.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DeepMyst/Mysti/ | [email protected] | ProductSource CodeVendor |
| https://github.com/DeepMyst/Mysti/commit/9b4aff0f106db424aa45a35aa89dd0b8f2eb9a48 | [email protected] | Source CodeVendor |
| https://github.com/DeepMyst/Mysti/issues/42 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/DeepMyst/Mysti/pull/43 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-13591 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/844480 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/374594 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/374594/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DeepMyst Mysti | 0.4.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion