GHSA-cm72-j98h-q99gCriticalCVSS 8.6

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom...

Published
August 21, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.

🔗 References (5)