Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2. | |
| Title | CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` | |
| Weaknesses | CWE-306 CWE-639 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T20:19:30.108Z
Reserved: 2026-07-17T14:11:15.483Z
Link: CVE-2026-63647
Updated: 2026-09-18T20:19:26.059Z
Status : Received
Published: 2026-09-18T20:17:20.773
Modified: 2026-09-18T21:17:04.883
Link: CVE-2026-63647
No data.
OpenCVE Enrichment
No data.