Insecure Direct Object Reference in American Archive of Public Broadcasting
Summary
Hide β²
Show βΌ
The American Archive of Public Broadcasting (AAPB) website contained an insecure direct object reference (IDOR) flaw that allowed unauthorized access to protected and private media files. The vulnerability was exploited since at least 2021 and was quietly patched in September 2025. The flaw was first reported by an anonymous researcher and later confirmed by AAPB. The bug allowed users to bypass access controls by manipulating media IDs in requests, enabling unauthorized downloads of restricted content. The exploit circulated among data hoarder communities on Discord, leading to the unauthorized sharing of protected media, including a leaked episode of Sesame Street. The AAPB is a public nonprofit archive operated by WGBH Educational Foundation and the Library of Congress, dedicated to preserving historically significant public media content in the United States.
Timeline
-
22.09.2025 23:25 π° 1 articles Β· β± 9h ago
IDOR flaw in AAPB website exploited since 2021, patched in September 2025
A vulnerability in the American Archive of Public Broadcasting's website allowed unauthorized access to protected and private media files since at least 2021. The flaw was quietly patched in September 2025. The exploit involved manipulating media IDs in requests to bypass access controls, enabling unauthorized downloads of restricted content. The exploit circulated among data hoarder communities on Discord, leading to the unauthorized sharing of protected media, including a leaked episode of Sesame Street.
Show sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
Information Snippets
-
The AAPB website had an IDOR vulnerability that allowed unauthorized access to protected media files.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The flaw was exploited since at least 2021 and was patched in September 2025.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The exploit was initially reported by an anonymous cybersecurity researcher.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The exploit involved manipulating media IDs in requests to bypass access controls.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The exploit circulated among data hoarder communities on Discord, leading to unauthorized sharing of protected media.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The AAPB is operated by WGBH Educational Foundation and the Library of Congress.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The exploit was a simple Tampermonkey script that exploited an IDOR flaw.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The vulnerability allowed users to request media files by ID, bypassing access controls.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25
-
The exploit was used to access and share a leaked episode of Sesame Street.
First reported: 22.09.2025 23:25π° 1 source, 1 articleShow sources
- American Archive of Public Broadcasting fixes bug exposing restricted media β www.bleepingcomputer.com β 22.09.2025 23:25