GHSA-3w65-9g38-h8jvHigh

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.

It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.

🔗 References (3)