| CVE | Icon | Vulnerability name | Date | Responsible Security Disclosure by | Stars | Process | Vulnerabilities |
|---|---|---|---|---|---|---|---|
| - | ExportScopeBleed | 2026-09-27 | xet7 | Found and fixed while reviewing native Scrum export permissions; board visibility did not enforce assigned-only card access. | Board-wide exporters accepted private-board visibility for assigned-only members while reading unassigned cards and related data. All nine exporter authorization methods now share an assignment-aware decision. Unfiltered exports are refused for assigned-only members; explicitly scoped Scrum reports retain access. CWE-863. High severity. No CVE assigned. Fix prepared for the Upcoming release. |
Source fix and regression coverage
Source audit, fix and verification scope
Ordinary export menus can lead assigned-only users to unsupported exports. A refusal alone cannot identify an attack, so no new account-blocking canary is added. Existing generic export-denial logging remains.
Policy tests cover all assigned-only roles and preserve ordinary member access and scoped Scrum charts. A source regression covers all nine exporter authorization methods; HTTP tests cover native JSON, ZIP, CSV, calendar, PDF, Excel and chart formats. Local verification uses Chromium, Meteor and MongoDB; other browsers, FerretDB and Sandstorm were not exercised.