Decidim是Decidim组织开源的一个参与式民主框架,用 Ruby on Rails 编写。 Decidim 0.31.5之前版本和0.32.0.rc1至0.32.0.rc2之前版本存在授权问题漏洞,该漏洞源于JWT支持的API身份验证未绑定到当前主机所选组织,导致一个租户签发的JWT可被重放到另一个租户的API,从而读取participantDetails数据并访问proposal.answer变更路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45378 | 7.5 HIGH | Decidim: Verification documents can be downloaded through reusable links |
| CVE-2026-45573 | 6.4 MEDIUM | Decidim: Push subscriptions can be abused for server-side requests |
| CVE-2026-45415 | 6.0 MEDIUM | Decidim: CSV census record endpoints improper authorization |
| CVE-2026-45572 | 4.8 MEDIUM | Decidim: HTML content blocks allow stored script execution |
No comments yet