Security: pdovhomilja/nextcrm-app
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
RBAC Bypass in MCP Project Tools Allows Shared Users to Tamper with Project Boards and TasksGHSA-vq6p-3qj5-p666 published
Jul 22, 2026 by pdovhomiljaHigh -
RBAC Bypass in MCP Product Tools Allows Low-Privileged Users to Modify the CRM Product CatalogGHSA-wv63-cq38-qg58 published
Jun 13, 2026 by pdovhomiljaHigh -
BOLA/IDOR in MCP Campaign Tools Allows Cross-User Campaign Disclosure and TamperingGHSA-c9vg-c532-ppqx published
Jun 13, 2026 by pdovhomiljaHigh -
BOLA/IDOR in PATCH /api/crm/contacts/[id] allowing Cross-Tenant CRM Data TamperingGHSA-mg5f-m89f-4gmc published
May 17, 2026 by pdovhomiljaHigh -
[HIGH] Broken Access Control in Server Actions allows any authenticated user to deactivate/activate arbitrary accountsGHSA-gm7p-f88p-vhfr published
May 17, 2026 by pdovhomiljaHigh -
Server-Side Request Forgery (SSRF) in nextcrm-appGHSA-f5r5-f2v5-74ww published
Jul 22, 2026 by pdovhomiljaCritical -
Pervasive Missing Authorization: Privilege Escalation + IDOR Across All API EndpointsGHSA-qwhm-9fcm-p878 published
Jul 22, 2026 by pdovhomiljaCritical
Learn more about advisories related to pdovhomilja/nextcrm-app in the GitHub Advisory Database