Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
UnratedPublic exploit

Improper Authorization in DeepMyst Mysti Contact Tracking

IdentifiersCVE-2026-13591CWE-285

CVE-2026-13591 affects DeepMyst Mysti 0.4.0 in the Contact Tracking component. The vulnerable code is the _isTrackedConversation function in src/managers/ChannelBridge.ts. According to the provided information, manipulation of the _channelType argument can cause an improper authorization condition, allowing authorization checks tied to tracked conversations to be bypassed or incorrectly evaluated. The issue is remotely reachable, but exploitation is described as difficult and requiring high attack complexity. A public exploit is reportedly available.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow a remote attacker to bypass intended authorization logic within the Contact Tracking functionality. This may permit unauthorized access to or interaction with tracked conversation-related functionality or data that should be restricted by channel type validation or authorization checks. The precise downstream impact beyond authorization bypass is not specified in the provided information.

Mitigation

If you can’t patch tonight, do this now.

Until the patch can be applied, restrict remote access to the affected Mysti instance and any interfaces exposing the Contact Tracking functionality. Add compensating controls around authorization-sensitive operations, including strict server-side validation of channel type values and logging/monitoring for anomalous tracked-conversation access attempts. If feasible, disable or limit the affected Contact Tracking feature until remediation is complete.

Remediation

Patch, then assume compromise.

Apply the vendor patch identified as commit 9b4aff0f106db424aa45a35aa89dd0b8f2eb9a48. If available, upgrade to a release that includes this fix. Validate that authorization decisions in the Contact Tracking component no longer rely on attacker-manipulable _channelType input without proper server-side enforcement.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

ACTIVITY FEED

Recent activity

7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity7

Community discussion across Reddit, Mastodon, and other social sources.