-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the 'skip_before_action' directive disabling CSRF protection for the preview endpoint. The commit diff shows this line was added in the vulnerable version and removed in the patch. The CWE-352 (CSRF) mapping and advisory details confirm this configuration error directly enables CSRF attacks on the preview functionality.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| decidim-templates | rubygems | >= 0.23.0, < 0.27.5 | 0.27.5 |
Ongoing coverage of React2Shell