Impact
The vulnerability is a source IDOR in Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint that allows an authenticated user or a project‑scoped API key holder to retrieve source details belonging to another tenant by providing a different source identifier. This flaw exposes the unredacted credentials for AMQP, Kafka, SQS, or Google PubSub, giving the attacker direct access to downstream messaging systems and compromising confidentiality.
Affected Systems
The issue affects the Convoy webhook gateway distributed by frain-dev. Any deployment running a Convoy instance prior to release v26.6.8 is vulnerable. The fix was introduced in that version; earlier releases remain at risk.
Risk and Exploitability
The CVSS score of 7.1 classifies the problem as High severity. The EPSS score of 0.0034 indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV. The flaw requires authenticated access—either user credentials or a project‑scoped API key—so an attacker must first possess valid authentication. Once authenticated, the IDOR permits arbitrary source‑detail disclosure across tenants, revealing messaging‑broker credentials and potentially enabling lateral movements. Based on the description, it is inferred that an attacker can exploit this by sending a crafted GET request with a target source ID.
OpenCVE Enrichment
Github GHSA