Advisories
Security advisories
One entry per security defect that reached a released version and met the threshold below. Written for somebody who deployed the version before the fix, which is a different reader from somebody choosing whether to upgrade.
When something gets an advisory
Every security correction is named in the changelog, in full. Above a threshold it also gets one of these, so a reader can answer the question a release note cannot: was I affected, and what do I do?
The threshold, written down so it is a rule rather than a decision made under pressure: a vulnerability in a released version involving an authentication or authorisation bypass, cross-tenant access, unauthorised exposure of customer data, remote code execution, a credential or secret compromise, High or Critical severity, known exploitation, or any issue requiring an action from you.
An issue that never reached a released version does not get one. It was never anybody’s exposure, and an advisory for it would be theatre.
To report something, see trust.
EVD-2026-001 — Unauthenticated requests reached project data
| Severity | Critical |
| Affected versions | Deployments running in token mode before 3.0.0 |
| Fixed in | 3.0.0 |
| Disclosed | 2026-09-07 |
| Impact | In deployments configured to require a sign-in, the middleware that names the caller logged that a request would be refused and refused none of them, leaving each controller to decide for itself. Only the admin module did. Anybody holding a project identifier could read that project’s assessment — its findings, its evidence and its decisions — over the internet, with no credential. |
| Preconditions | The deployment was running in token mode, was reachable from a network the reporter was on, and the reader knew or guessed a project identifier. A local-mode deployment attributes every request to the one operator on the machine and was not affected. |
| What to do | Upgrade to 3.0.0 or later. There is no configuration change that closes it on an earlier version, because the defect is in the code path that decides. |
| How to tell whether it happened | Access logs for the period show requests to /api/v1/ paths other than health, session configuration, contact and demonstration, carrying no bearer token and answered with 200. |
| Reported by | Found in-house, while checking whether a public claim about this platform was true. |