EVIDENT

Advisories

Security advisories

One entry per security defect that reached a released version and met the threshold below. Written for somebody who deployed the version before the fix, which is a different reader from somebody choosing whether to upgrade.

When something gets an advisory

Every security correction is named in the changelog, in full. Above a threshold it also gets one of these, so a reader can answer the question a release note cannot: was I affected, and what do I do?

The threshold, written down so it is a rule rather than a decision made under pressure: a vulnerability in a released version involving an authentication or authorisation bypass, cross-tenant access, unauthorised exposure of customer data, remote code execution, a credential or secret compromise, High or Critical severity, known exploitation, or any issue requiring an action from you.

An issue that never reached a released version does not get one. It was never anybody’s exposure, and an advisory for it would be theatre.

To report something, see trust.

EVD-2026-001 — Unauthenticated requests reached project data

SeverityCritical
Affected versionsDeployments running in token mode before 3.0.0
Fixed in3.0.0
Disclosed2026-09-07
ImpactIn deployments configured to require a sign-in, the middleware that names the caller logged that a request would be refused and refused none of them, leaving each controller to decide for itself. Only the admin module did. Anybody holding a project identifier could read that project’s assessment — its findings, its evidence and its decisions — over the internet, with no credential.
PreconditionsThe deployment was running in token mode, was reachable from a network the reporter was on, and the reader knew or guessed a project identifier. A local-mode deployment attributes every request to the one operator on the machine and was not affected.
What to doUpgrade to 3.0.0 or later. There is no configuration change that closes it on an earlier version, because the defect is in the code path that decides.
How to tell whether it happenedAccess logs for the period show requests to /api/v1/ paths other than health, session configuration, contact and demonstration, carrying no bearer token and answered with 200.
Reported byFound in-house, while checking whether a public claim about this platform was true.