ManageBoardBleed

CVEIconVulnerability nameDateResponsible Security Disclosure byStarsProcessVulnerabilities
-

ManageBoardBleed 2026-09-14 Wenhao Wu, Southeast University Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation.

REST management endpoints incorrectly accepted ordinary write capability. Title, card-settings and rule mutation endpoints now require board or site administrator privileges, aligning with DDP. Unauthorized management attempts are summarized in Problems; logging cannot break refusal.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.

Details

REST management endpoints incorrectly accepted ordinary write capability. Title, card-settings and rule mutation endpoints now require board or site administrator privileges, aligning with DDP. Unauthorized management attempts are summarized in Problems; logging cannot break refusal.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.