InvitationBoardBleed

CVEIconVulnerability nameDateResponsible Security Disclosure byStarsProcessVulnerabilities
-

InvitationBoardBleed 2026-09-14 Wenhao Wu, Southeast University Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation.

When domain-approved users could send registration invitations, the supplied board list was stored without board authorization. The complete list now requires existing boards and the same configured inviter-role policy as board invitations, with a site-admin bypass. Denied grants are summarized in Problems. Live mail delivery and redemption remain unverified.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.

Details

When domain-approved users could send registration invitations, the supplied board list was stored without board authorization. The complete list now requires existing boards and the same configured inviter-role policy as board invitations, with a site-admin bypass. Denied grants are summarized in Problems. Live mail delivery and redemption remain unverified.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.