CVE-2026-86544

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 23:16

Updated : 2026-09-09 15:17


NVD link : CVE-2026-86544

Mitre link : CVE-2026-86544

CVE.ORG link : CVE-2026-86544


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization