{"id":"CVE-2019-14537","details":"YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.","aliases":["GHSA-vf23-f26f-mjj9"],"modified":"2026-07-08T17:17:35.991750Z","published":"2019-08-07T17:15:12.337Z","references":[{"type":"ADVISORY","url":"https://github.com/YOURLS/YOURLS/releases"},{"type":"FIX","url":"https://github.com/YOURLS/YOURLS/commits/master"},{"type":"FIX","url":"https://github.com/YOURLS/YOURLS/pull/2542"},{"type":"EVIDENCE","url":"https://github.com/Wocanilo/CVE-2019-14537"},{"type":"EVIDENCE","url":"https://security-garage.com/index.php/cves/cve-2019-14537-api-authentication-bypass-via-type-juggling"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yourls/yourls","events":[{"introduced":"0"},{"last_affected":"077018822d3594229daa8343310d0b40804b9ddc"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.7.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:yourls:yourls:*:*:*:*:*:*:*:*"}}],"versions":["1.7.3","1.7.1","1.7.2","1.7","1.6","1.5.1","1.5","1.4.3","1.4.2","1.4.1","1.4","1.2","1.1","1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14537.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}