Vendor
Typemill versions prior to 2.26.0 are susceptible to an authorization bypass vulnerability that allows unauthenticated attackers to download restricted media files via path manipulation.