Security: ever-co/ever-gauzy
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Host-injection SSRF via unvalidated Make.com `zone` (authenticated, response-returned)GHSA-vcwx-qh95-54g6 published
Aug 10, 2026 by evereqModerate -
Excessive data exposure on public-share employee & organization endpointsGHSA-49ff-8859-537j published
Aug 10, 2026 by evereqHigh -
Stored SSRF via Make.com integration webhook URL (no egress filter)GHSA-534m-c6mh-mp98 published
Aug 10, 2026 by evereqHigh -
Unauthenticated SQL injection in plugin marketplace search (`ORDER BY`)GHSA-xqcf-j9jr-7w59 published
Aug 10, 2026 by evereqCritical -
Cross-tenant GitHub private-repository access via unverified GitHub-App installation_id (CWE-639)GHSA-4rwq-65wh-45h4 published
Aug 10, 2026 by evereqHigh -
Cross-tenant IDOR: the SharedEntity feature does not verify that the shared entityId belongs to the caller's tenant, and the public share-token endpoint resolves the target entity by id with no tenant scope — letting a user read another tenant's Employee/Invoice/User records (attacker-chosen fields), unauthenticated, via the tokenGHSA-gpg5-qwjc-8hqh published
Aug 10, 2026 by evereqModerate -
Cross-tenant data disclosure via unauthenticated SharedEntity token endpoint lacking tenant isolationGHSA-cx2q-xmh2-pc38 published
Aug 10, 2026 by evereqModerate -
Prototype Pollution via deepMerge in resend email verification endpoint (POST /auth/email/verify/resend-link)GHSA-qfc6-v3g6-rxf8 published
Aug 10, 2026 by evereqHigh -
Incomplete role-change check in user profile update allows any authenticated employee to escalate to SUPER_ADMINGHSA-x4mv-fhwj-g3rp published
Aug 10, 2026 by evereqHigh -
Default JWT signing secret in shipped configuration files enables full account takeoverGHSA-chm8-2ggf-pgjq published
Aug 10, 2026 by evereqCritical
Learn more about advisories related to ever-co/ever-gauzy in the GitHub Advisory Database