Skip to content

Commit a78e25c

Browse files
authored
docs(security): add latest published advisory
1 parent a542c1f commit a78e25c

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -82,6 +82,9 @@ If you follow these guidelines, we won’t pursue or support legal action.
8282
- **GHSA-6c3j-f4x4-36m3** / **CVE-2026-33330**`< 3.10.0`: FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback.
8383
**Fixed in:** **3.10.0** and later. Thanks to **bg0d-glitch** for responsible disclosure.
8484

85+
- **GHSA-62wx-vp78-2p83** / **CVE-2026-33477** - `< 3.11.0`: Incorrect authorization in /api/file/snippet.php allows read_own users to read other users’ file content
86+
**Fixed in: 3.11.0** and later. Thanks to **bg0d-glitch** for responsible disclosure.
87+
8588
Thanks to **[@kiwi865](https://github.com/kiwi865)**, **[@ByteTyson](https://github.com/ByteTyson)**, **[@x0root](https://github.com/x0root)**, **n0rv-TvT**, **kq5y**, and **bg0d-glitch** for responsible disclosure of issues.
8689

8790
## Questions

0 commit comments

Comments
 (0)