InviteProfileBleed

CVEIconVulnerability nameDateResponsible Security Disclosure byStarsProcessVulnerabilities
-

InviteProfileBleed 2026-09-14 Wenhao Wu, Southeast University Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation.

Removed members could forge profile.invitedBoards and call acceptInvite to reactivate their retained membership row. Client permission gates now protect that capability, including operator paths, parent replacement and rename destinations. Ordinary leaf preferences remain editable. Denied invitation changes appear as bounded Problems summaries; logging cannot break refusal.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.

Details

Removed members could forge profile.invitedBoards and call acceptInvite to reactivate their retained membership row. Client permission gates now protect that capability, including operator paths, parent replacement and rename destinations. Ordinary leaf preferences remain editable. Denied invitation changes appear as bounded Problems summaries; logging cannot break refusal.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.