LinkedWriteBleed

CVEIconVulnerability nameDateResponsible Security Disclosure byStarsProcessVulnerabilities
-

LinkedWriteBleed 2026-09-14 Wenhao Wu, Southeast University Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation.

Comment-only source members could create links on self-owned boards and use delegated write checks to modify the source. Source write access is now required for method and DDP link creation and pointer changes. Explicit non-writing source roles cap delegation through legacy links. UI permissions follow the ceiling. Denied attempts use bounded Problems summaries.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.

Details

Comment-only source members could create links on self-owned boards and use delegated write checks to modify the source. Source write access is now required for method and DDP link creation and pointer changes. Explicit non-writing source roles cap delegation through legacy links. UI permissions follow the ceiling. Denied attempts use bounded Problems summaries.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.