-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing cascading deletion logic in resource deletion endpoints. The commit diff shows all four resources (collaboration, user, role, task) received 'delete_dependents' flag handling and dependency cleanup logic. The original functions lacked these checks, leaving linked resources undeleted. The patch explicitly adds conditional deletion of child resources, confirming these functions were vulnerable prior to version 4.0.0.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| vantage6 | pip | < 4.0.0 | 4.0.0 |
Ongoing coverage of React2Shell