The validateCopy endpoint failed to enforce object-level authorization, letting a user read and copy objects belonging to other projects (insecure direct object reference).
Cross-project IDOR in the validateCopy endpoint.
cve.org record · GitHub Security Advisory GHSA-p527-vjfp-c43p