-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| vantage6 | pip | < 4.2.0 | 4.2.0 |
The vulnerability stemmed from missing encryption validation in the task creation workflow. The patch adds a new _check_input_encryption method and calls it from post_task, indicating this was the vulnerable entry point. The pre-patch version of post_task proceeded with task creation without verifying if unencrypted input was being stored in an encrypted collaboration, violating the intended security controls.
Ongoing coverage of React2Shell