Security: canyongbs/advisingapp
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Stored XSS in Customer Advisor transcript modal allows privilege escalation from unauthenticated widget user to staff/admin sessionGHSA-hpg3-vwx3-m282 published
Jun 9, 2026 by OrrisonCritical -
Permissive CORS configuration allows origin reflection with credentials on API pathsGHSA-6qqv-72w5-p2hc published
Jun 9, 2026 by OrrisonModerate
Learn more about advisories related to canyongbs/advisingapp in the GitHub Advisory Database