SubtaskDepositBleed

CVEIconVulnerability nameDateResponsible Security Disclosure byStarsProcessVulnerabilities
-

SubtaskDepositBleed 2026-09-14 Wenhao Wu, Southeast University Responsible disclosure through a saved GitHub security advisory; current code and sibling paths reviewed during remediation.

An unvalidated deposit pointer bridged private cards and related content into the source board feed, and subtask creation skipped destination write authorization. Source card scopes now exclude foreign pointers and null IDs. Deposit content follows a reactive authorized board cursor with its own assignment restrictions. Assigned-card content follows reactive card cursors. Writes and pointer changes require destination write access. Write refusals are summarized in Problems; ordinary filtered reads are not attack events.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.

Details

An unvalidated deposit pointer bridged private cards and related content into the source board feed, and subtask creation skipped destination write authorization. Source card scopes now exclude foreign pointers and null IDs. Deposit content follows a reactive authorized board cursor with its own assignment restrictions. Assigned-card content follows reactive card cursors. Writes and pointer changes require destination write access. Write refusals are summarized in Problems; ordinary filtered reads are not attack events.

Source fix and regression coverage. Targeted tests pass; live browser execution remains pending. No CVE is assigned here.