Skip to content

Commit 4e6563f

Browse files
authored
docs(security): add published 2026 advisories and reporter credits
1 parent 1f97156 commit 4e6563f

1 file changed

Lines changed: 16 additions & 1 deletion

File tree

SECURITY.md

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,22 @@ If you follow these guidelines, we won’t pursue or support legal action.
6767
- **GHSA-jm96-2w52-5qjj**`v1.4.0`: Insecure folder visibility via name-based mapping and incomplete ACL checks.
6868
**Fixed in:** **1.5.0** and later.
6969

70-
Thanks to **[@kiwi865](https://github.com/kiwi865)** & **[@ByteTyson](https://github.com/ByteTyson)** & **[@x0root](https://github.com/x0root)** for responsible disclosure of issues.
70+
- **GHSA-vh5m-w36c-99xv** / **CVE-2026-33070**`< 3.8.0`: Unauthenticated Share Link Deletion.
71+
**Fixed in:** **3.8.0** and later. Thanks to **n0rv-TvT** for responsible disclosure.
72+
73+
- **GHSA-46gv-gf5f-wvr2** / **CVE-2026-33071**`< 3.8.0`: WebDAV upload path bypasses filename validation enforced by regular uploads.
74+
**Fixed in:** **3.8.0** and later. Thanks to **n0rv-TvT** for responsible disclosure.
75+
76+
- **GHSA-f4xx-57cv-mg3x** / **CVE-2026-33072**`< 3.9.0`: Default Encryption Key Enables Token Forgery and Config Decryption.
77+
**Fixed in:** **3.9.0** and later. Thanks to **n0rv-Tv** for responsible disclosure.
78+
79+
- **GHSA-c2jm-4wp9-5vrh** / **CVE-2026-33329**`< 3.10.0`: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle.
80+
**Fixed in:** **3.10.0** and later. Thanks to **kq5y** for responsible disclosure.
81+
82+
- **GHSA-6c3j-f4x4-36m3** / **CVE-2026-33330**`< 3.10.0`: FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback.
83+
**Fixed in:** **3.10.0** and later. Thanks to **bg0d-glitch** for responsible disclosure.
84+
85+
Thanks to **[@kiwi865](https://github.com/kiwi865)**, **[@ByteTyson](https://github.com/ByteTyson)**, **[@x0root](https://github.com/x0root)**, **n0rv-TvT**, **n0rv-Tv**, **kq5y**, and **bg0d-glitch** for responsible disclosure of issues.
7186

7287
## Questions
7388

0 commit comments

Comments
 (0)