No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cjgj-2fwf-4c2w | Perses's project query parameter authorization bypass exposes cross-project resources |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3. | |
| Title | Perses project query parameter authorization bypass exposes cross-project resources | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T19:50:33.901Z
Reserved: 2026-07-16T21:37:45.768Z
Link: CVE-2026-63458
Updated: 2026-09-18T19:50:29.857Z
Status : Received
Published: 2026-09-18T18:17:10.643
Modified: 2026-09-18T20:17:20.510
Link: CVE-2026-63458
No data.
OpenCVE Enrichment
No data.
-
CWE-639
Authorization Bypass Through User-Controlled Key
Github GHSA