| CVE | Icon | Vulnerability name | Date | Responsible Security Disclosure by | Stars | Process | Vulnerabilities |
|---|---|---|---|---|---|---|---|
| - | HistoryScopeBleed | 2026-09-27 | xet7 | Found and fixed while integrating Scrum with universal History; current access and historical authorship were not consistently separated. | Universal History returned hidden cards to assigned-only members and could retain private-board history access after membership was removed. Its reversal path could also use an old board’s access to edit a card now on another board. Reads now enforce current scope before searching or counting; restore, undo and redo share current scope and card edit checks. CWE-863. High severity. No CVE assigned. Fix prepared for the Upcoming release. |
Source fix and regression coverage
Routine history filtering is not an attack signal. A refused restoration may follow a legitimate concurrent reassignment or permission change, so this guard does not automatically classify those refusals as account-blocking attacks. Existing linked-card policy logging remains unchanged.
Positive and negative tests cover currently visible history, assigned-only cards, hidden search results and contributor counts, revoked private-board access, authorized restoration and denied edits to moved cards. Existing rule undo/redo and stale-state regressions also pass. Verification uses Chromium, Meteor and MongoDB; other browsers, FerretDB and Sandstorm were not exercised.