GHSA-q52j-357p-5pv8HighCVSS 8.1

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code...

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.

🔗 References (8)