OSV 1.4.0 · github-reviewed · 修改于 2026-07-14 01:16
发布时间
2026-07-14 01:16
GitHub 审查时间
2026-07-14 01:16
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-r3v7-5x4c-c69q/GHSA-r3v7-5x4c-c69q.json
A JWT issued to an Org 1 account is accepted on the Org 2 API and can read the admin-only GraphQL participantDetails field for an Org 2 participant. The same trust-boundary problem also affects API-user authentication: an Org 1 API user can use a JWT on the Org 1 host and replay that JWT to the Org 2 API to read Org 2 participant personal data and reach Org 2's proposal.answer mutation path.
The current host selects the Decidim organization context, but JWT-backed API authentication is not sufficiently bound to that host organization. As a result, the API can process a request in Org 2's context while still trusting an authenticated principal from Org 1.
Reproduction steps:
org2.localhost:3001Note that using a participant-generated JWT did not allow showing these results.
A JWT issued for one organization can be replayed successfully against another organization's API and used to retrieve sensitive details from that organization.
See https://github.com/decidim/decidim/pull/16673 and https://github.com/decidim/decidim/pull/16756
Disable JWT credentials on system panel (/system)
OWASP A01:2021 Broken Access Control
This issue was discovered in a security audit organized by the and made by against Decidim financed by .