GHSA-r3v7-5x4c-c69q
HIGHCVE-2026-45414A JWT issued to an Org 1 account is accepted on the Org 2 API and can read the admin-only GraphQL participantDetails field for an Org 2 participant. The same trust-boundary problem also affects API-user authentication: an Org 1 API user can use a JWT on the Org 1 host and replay that JWT to the Org 2 API to read Org 2 participant personal data and reach Org 2's proposal.answer mutation path.
- Affected
- < 0.31.5
- Fixed in
- 0.31.5
- Weakness
- CWE-287
- Published
- 2026-07-13
- Source
- github