Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwj4-f78f-jj3j

Опубликовано: 10 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.3

Описание

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.

EPSS

Процентиль: 19%
0.00268
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.3
nvd
13 дней назад

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.

EPSS

Процентиль: 19%
0.00268
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-863