OSV 1.4.0 · github-reviewed · 修改于 2026-07-03 00:04
发布时间
2026-07-03 00:04
GitHub 审查时间
2026-07-03 00:04
NVD 发布时间
2026-06-12 05:16
源文件
advisories/github-reviewed/2026/07/GHSA-chr9-m4q2-76hw/GHSA-chr9-m4q2-76hw.json
In affected LAN/shared-token Control UI deployments, a caller could spoof locality information used during Control UI pairing and obtain a durable admin-capable device token.
This issue is limited to deployments where the caller already has the network/authentication foothold needed to reach the Control UI pairing path. It is not an unauthenticated internet exposure issue.
This affects configurations such as LAN-bound gateways or shared-token Control UI access where locality signals were accepted as sufficient for pairing decisions.
A temporary or shared Control UI access path could be turned into a persistent admin device token. That token could remain useful after the shared gateway token was rotated, unless the paired device was removed.
The issue is a pairing/locality validation problem: locality-derived trust was stronger than it should have been.
The first stable patched version is 2026.5.22.
Upgrade to [email protected] or later. For older deployments, remove unexpected paired devices and avoid exposing Control UI pairing paths on networks with untrusted clients.