GHSA-chx7-hm9p-hcvgMediumCVSS 4.3

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's...

Published
September 16, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.

🔗 References (10)