Incorrect Authorization Affecting mythic package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-MYTHIC-17751534
  • published1 Jul 2026
  • disclosed29 Jun 2026
  • creditUnknown

Introduced: 29 Jun 2026

CVE-2026-57951  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

mythic is an Interact with Mythic C2 Framework Instances

Affected versions of this package are vulnerable to Incorrect Authorization due to a broken permission filter in the payload_build_step table, which uses an always-satisfied _or condition that bypasses operation-scoped access controls. An attacker can access sensitive information, including step_stdout, step_stderr, step_name, and step_description from all operations by sending crafted queries as an authenticated operator or spectator.

CVSS Base Scores

version 4.0
version 3.1