{"id":"CVE-2021-41191","details":"Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, add `@require_apikey` in `BOT/lib/cogs/website.py` under the route for `/v1/products`.","aliases":["GHSA-76mx-6584-4v8q"],"modified":"2026-07-09T15:01:39.411410Z","published":"2021-10-27T21:15:08.133Z","references":[{"type":"ADVISORY","url":"https://github.com/Redon-Tech/Roblox-Purchasing-Hub/releases/tag/V1.0.2"},{"type":"ADVISORY","url":"https://github.com/Redon-Tech/Roblox-Purchasing-Hub/security/advisories/GHSA-76mx-6584-4v8q"},{"type":"FIX","url":"https://github.com/Redon-Tech/Roblox-Purchasing-Hub/commit/58a22260eca40b1a0377daf61ccd8c4dc1440e03"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redon-tech/roblox-purchasing-hub","events":[{"introduced":"0"},{"fixed":"58a22260eca40b1a0377daf61ccd8c4dc1440e03"}],"database_specific":{"cpe":"cpe:2.3:a:redon:roblox_purchasing_hub:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.0.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["V1.1","V1.0.1","V1.0","V0.9","V0.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41191.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}