{"id":"PYSEC-2026-675","summary":"MoinMoin Improper ACL handling for calendars and includes","details":"MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.","aliases":["CVE-2007-2637","GHSA-cmg7-xr2j-4r9v"],"modified":"2026-07-06T08:00:44.815511720Z","published":"2026-07-02T14:13:20.287938Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2637"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34474"},{"type":"WEB","url":"https://moinmo.in/MoinMoinRelease1.5/CHANGES"},{"type":"WEB","url":"http://osvdb.org/36269"},{"type":"WEB","url":"http://secunia.com/advisories/25208"},{"type":"WEB","url":"http://secunia.com/advisories/29262"},{"type":"WEB","url":"http://www.debian.org/security/2008/dsa-1514"},{"type":"WEB","url":"http://www.ubuntu.com/usn/usn-458-1"},{"type":"PACKAGE","url":"https://pypi.org/project/moin"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cmg7-xr2j-4r9v"}],"affected":[{"package":{"name":"moin","ecosystem":"PyPI","purl":"pkg:pypi/moin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.8"}]}],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/moin/PYSEC-2026-675.yaml"}}],"schema_version":"1.7.5"}