knowns vulnerability

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.

Published 7 Sep 2026Updated 7 Sep 20266 sources
CVSS 7.2

Source timeline

CVE record published by NVDView source ↗