| CVE | Icon | Vulnerability name | Date | Responsible Security Disclosure by | Stars | Process | Vulnerabilities |
|---|---|---|---|---|---|---|---|
| - | MutationBleed | 2026-09-14 | Wenhao Wu, Southeast University | ![]() ![]() ![]() ![]() ![]() |
Responsible disclosure through a saved GitHub security advisory; membership-only method guards and their siblings reviewed during remediation. |
|
Server methods bypass collection allow/deny. Membership alone does not grant write access: comment-only, comment-assigned-only, worker and read-only roles cannot perform general board mutations.
Both sides of list, swimlane and checklist moves, scoped import, attachment rename and history write paths now enforce the canonical role capability. The No comments role keeps its intended write access. Denied attempts use bounded Problems summaries; logging cannot break enforcement.
Source fix and regression coverage. Role decisions, reported moveList attack and sibling inventory tests pass. Browser regression added and syntax-checked; live execution pending. No CVE is assigned here.