GHSA-v667-gc2r-2xm7
CRITICALCVE-2026-55445The init guard middleware in Qinglong only checks /api/user/init paths but not /open/user/init, which is whitelisted from JWT authentication and rewritten to /api/user/init after the guard has already passed, allowing unauthenticated admin credential reset on initialized instances.
- Affected
- < 2.20.1
- Fixed in
- 2.20.1
- Weakness
- CWE-287
- Published
- 2026-08-20
- Source
- github