RuleButtonBleed

CVEIconVulnerability nameDateResponsible Security Disclosure byStarsProcessVulnerabilities
-

RuleButtonBleed 2026-09-14 Wenhao Wu, Southeast University Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation.

Manual button rules accepted non-writing members and unbound card IDs. Both the method and shared action dispatcher now require write access and authoritative card-to-rule board binding before executing actions. Cardless board buttons remain supported. Denied contexts are summarized in Problems; logging cannot break refusal.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.

Details

Manual button rules accepted non-writing members and unbound card IDs. Both the method and shared action dispatcher now require write access and authoritative card-to-rule board binding before executing actions. Cardless board buttons remain supported. Denied contexts are summarized in Problems; logging cannot break refusal.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.