← CVEs and Advisories

CVE-2026-63014

NationalSecurityAgency/skills-service · Severity Medium (CVSS 4.3) · Discovered by Pavan Nallamothu

The validateCopy endpoint failed to enforce object-level authorization, letting a user read and copy objects belonging to other projects (insecure direct object reference).

Summary

Cross-project IDOR in the validateCopy endpoint.

References

cve.org record · GitHub Security Advisory GHSA-p527-vjfp-c43p