Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3w65-9g38-h8jv

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.

It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.

It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.

8.7 High

CVSS4

Дефекты

CWE-269

Связанные уязвимости

nvd
3 дня назад

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.

debian
3 дня назад

An authenticated, non-guest user of Curiosity Workspace could enroll t ...

8.7 High

CVSS4

Дефекты

CWE-269