A security issue in the runtime event system allows...
High severity
Unreviewed
Published
Aug 14, 2025
to the GitHub Advisory Database
•
Updated Aug 14, 2025
Description
Published by the National Vulnerability Database
Aug 14, 2025
Published to the GitHub Advisory Database
Aug 14, 2025
Last updated
Aug 14, 2025
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.
References