GHSA-49jg-8r6h-h4r7Medium

Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated...

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments should be returned, but previously had no role restriction beyond general API authentication.

As a result, a lower-privileged authenticated user could potentially query another user’s assignment information by supplying that user’s identifier.

The fix changes:

method_decorators = [api_required]

to:

method_decorators = [admin_or_org_admin_required, api_required]

so only administrators or organization administrators can perform cross-user assignment queries.

Version impacted =>3.3.0

🔗 References (3)