| CVE | Icon | Vulnerability name | Date | Responsible Security Disclosure by | Stars | Process | Vulnerabilities |
|---|---|---|---|---|---|---|---|
| - | AdminFieldBleed | 2026-09-28 | Hama1cco | Reported privately by Hama1cco through GitHub Security Advisory GHSA-m8gh-2h78-f57x; validated and fixed by xet7. | Non-admin board members could read admin-only custom-field values through raw card responses and set them during card creation or copying. Whole-array updates also bypassed the indexed-value guard. The fix enforces the value boundary on server publications, API and method results, card writes and exports, including live permission changes. Protected definition changes require administration of every affected board. CWE-863. High severity. No CVE assigned. Fix prepared locally for the Upcoming release; not yet released. |
Server-side redaction preserves field IDs and positions while concealing values. Live subscriptions retract values after board-admin access is lost or a field becomes admin-only. Ordinary public-field editing remains available.
All card mutation operators are checked against the protected before/after values. The driver boundary also covers server-side direct writes from authenticated HTTP and DDP requests. Copying omits values the caller cannot read.
Explicit protected-value or protected-definition mutation attempts are refused and summarized under AdminFieldBleed in Admin Panel → Problems. Normal reads are silently redacted. An ordinary export refusal is not classified as an attack.
Binary and streaming exports containing protected fields require board-admin access until they support value-level redaction. Public-board shortcuts do not bypass this restriction.
Source fix and regression tests
Regression coverage includes positive and negative Node tests, live REST/DDP browser checks, forged writes, History/search inference and the Problems summary. Local MongoDB, Meteor and Chromium were tested; production deployments, FerretDB and other browsers were not exercised.
See the boundary review and verification scope and the Upcoming changelog.