Skip to content
archivevulnerability · 18 Sep 2026 · 17:39 UTC

GHSA-4227-9989-jrhx: Perses's missing authorization in datasource proxy allows cross-scope secret disclosure

VULNCVE-2026-63199source · GTH
HIGHHigh-risk vulnerability

last 60 dispatches · spectrum

### Impact The datasource proxy authorizes the caller on the Datasource scope, then resolves and decrypts any Secret named in the request body with no Secret-scope check. Datasource and Secret are distinct, independently grantable role scopes, so an operator can grant datasource access without secret access. The proxy and the service to create a datasource does not verify that the operator has the correct right. A user holding only `GlobalDatasource:create` can create a `GlobalDatasource` and attached to it a `GlobalSecret` without having the right to get access to. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected