Impact
An authenticated user can accept or reject any amendment within Decidim, causing the user to be granted coauthor status on the original proposal. This privilege elevation allows the attacker to influence proposals beyond their own scope, potentially manipulating decision‑making processes and asserting authorship over content they did not create.
Affected Systems
Decidim versions 0.19.0 up through 0.30.4 and 0.31.0 are affected. Version 0.30.5 and 0.31.1 include the fix. All components that enable amendments, such as proposals, are subject to the vulnerability.
Risk and Exploitability
The vulnerability scores a CVSS of 7.5 and is not listed in CISA KEV, indicating a moderate‑to‑high risk but no confirmed exploitation record. The EPSS score is not available, suggesting limited data on current exploitation likelihood. The attack can be carried out by any registered and authenticated user by simply using the standard amendment acceptance or rejection UI, without requiring additional privileges or remote code execution.
OpenCVE Enrichment
Github GHSA