chartbrew是Chartbrew开源的一个数据可视化与仪表盘构建工具。 Chartbrew 4.9.0版本存在访问控制错误漏洞,该漏洞源于多个数据集和数据请求端点仅按团队级别授权低权限项目成员,未将请求的dataset_id、dataRequest id和connection_id绑定到调用者的允许项目,可能导致认证攻击者跨项目读取、执行、创建、更新和删除数据集及数据请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40600 | 8.1 HIGH | Chartbrew: Incorrect Access Control in project share policy routes via unbound policy_id |
| CVE-2026-40601 | 7.5 HIGH | Chartbrew: Missing Authorization in /api/chart/:chart_id/query via team-level refresh togg |
| CVE-2026-40595 | 7.5 HIGH | Chartbrew: Incorrect Access Control in public chart and export routes via missing onReport |
| CVE-2026-35514 | 6.5 MEDIUM | Unauthenticated Account Registration via /user/invited Bypasses All Signup Restrictions in |
| CVE-2026-40603 | 6.5 MEDIUM | Chartbrew: Incorrect Access Control in /api/project/dashboard/:brewName via same-team over |
No comments yet