Skip to content

[GHSA-5f42-97gr-vfhq] Add CWE-863 to GHSA-5f42-97gr-vfhq - #10213

Open
stanleys12 wants to merge 1 commit into
github:stanleys12/advisory-improvement-10213from
stanleys12:stanleys12-GHSA-5f42-97gr-vfhq
Open

stanleys12 wants to merge 1 commit into
github:stanleys12/advisory-improvement-10213from
stanleys12:stanleys12-GHSA-5f42-97gr-vfhq

Conversation

@stanleys12

Copy link
Copy Markdown

This advisory had no CWE, so I added one. The NVD entry for CVE-2026-85724 (https://nvd.nist.gov/vuln/detail/CVE-2026-85724) lists CWE-863 (Incorrect Authorization) from the GitHub CNA, plus CWE-155. CWE-863 fits the main problem: client IDs or usernames with + or # widen the pattern-ACL filters in AuthorizationsCollector.canDoOperation, so a client can get around cross-tenant authorization. I put CWE-863 in database_specific.cwe_ids.

@github-actions
github-actions Bot changed the base branch from main to stanleys12/advisory-improvement-10213 October 7, 2026 19:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant