GHSA-frgf-wpx9-58c9MediumCVSS 4.3

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.

🔗 References (7)