knowns vulnerability

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.

Published 7 Sep 2026Updated 7 Sep 20266 sources
CVSS 7.2

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.