| CVE | Icon | Vulnerability name | Date | Responsible Security Disclosure by | Stars | Process | Vulnerabilities |
|---|---|---|---|---|---|---|---|
| - | InvitationBoardBleed | 2026-09-14 | Wenhao Wu, Southeast University | ![]() ![]() ![]() ![]() ![]() |
Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation. | When domain-approved users could send registration invitations, the supplied board list was stored without board authorization. The complete list now requires existing boards and the same configured inviter-role policy as board invitations, with a site-admin bypass. Denied grants are summarized in Problems. Live mail delivery and redemption remain unverified. Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here. |
When domain-approved users could send registration invitations, the supplied board list was stored without board authorization. The complete list now requires existing boards and the same configured inviter-role policy as board invitations, with a site-admin bypass. Denied grants are summarized in Problems. Live mail delivery and redemption remain unverified.
Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.