Security: ever-co/ever-gauzy
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Public Invoice Link Accepts Unbound JWTs and Default Signing KeysGHSA-28wv-vrxj-rp4q published
Sep 26, 2026 by evereqHigh -
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') and Inclusion of Functionality from Untrusted Control Sphere in @gauzy/coreGHSA-48h9-vwf5-h8m7 published
Sep 26, 2026 by evereqHigh -
Cross-Tenant Global Invoice Number Sequence Leak via Unscoped Highest QueryGHSA-57hw-jqpj-ww97 published
Sep 26, 2026 by evereqModerate -
Cross-Tenant Entity Takeover via Primary Key Upsert in TenantAware Update HandlersGHSA-jh6m-9fxr-rx3c published
Sep 26, 2026 by evereqCritical -
CSV formula injection in data export (exported cells are not neutralized)GHSA-7xp5-j564-4752 published
Sep 26, 2026 by evereqModerate -
Social login accepts any valid provider access token without audience verification (account takeover)GHSA-58x4-7mw9-gmqg published
Sep 26, 2026 by evereqCritical -
Access tokens are signed with a hard-coded default secret when JWT_SECRET is unset (incomplete fix of GHSA-chm8-2ggf-pgjq)GHSA-39j7-x845-4w3c published
Sep 26, 2026 by evereqCritical -
Missing @Permissions on four mutating routes: the EMPLOYEE role can destroy a knowledge base, rewrite any article and rename any departmentGHSA-v79w-54p2-wmh5 published
Sep 26, 2026 by evereqHigh -
Authenticated (blind) SSRF via AI-provider credential baseUrl in the AI-chat pluginGHSA-w3mx-m5cr-3gxp published
Sep 26, 2026 by evereqModerate -
ever-gauzy: Cross-tenant user disclosure via email lookup and time-log IDOR (CWE-639/CWE-862)GHSA-6qvm-3wg4-26w4 published
Sep 26, 2026 by evereqHigh
Learn more about advisories related to ever-co/ever-gauzy in the GitHub Advisory Database