| CVE | Icon | Vulnerability name | Date | Responsible Security Disclosure by | Stars | Process | Vulnerabilities |
|---|---|---|---|---|---|---|---|
| - | RuleButtonBleed | 2026-09-14 | Wenhao Wu, Southeast University | ![]() ![]() ![]() ![]() ![]() |
Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation. | Manual button rules accepted non-writing members and unbound card IDs. Both the method and shared action dispatcher now require write access and authoritative card-to-rule board binding before executing actions. Cardless board buttons remain supported. Denied contexts are summarized in Problems; logging cannot break refusal. Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here. |
Manual button rules accepted non-writing members and unbound card IDs. Both the method and shared action dispatcher now require write access and authoritative card-to-rule board binding before executing actions. Cardless board buttons remain supported. Denied contexts are summarized in Problems; logging cannot break refusal.
Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.