Security: OpenFn/lightning
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Low-privilege users could set privileged project fields, invoke admin-only actions, and download unscrubbed secrets from history exportsGHSA-2j4r-h84j-x5v2 published
Jul 23, 2026 by stuartcHigh -
Lightning did not verify the PostgreSQL server certificate on SSL database connectionsGHSA-5rfg-wfvp-x3q9 published
Jul 23, 2026 by stuartcModerate -
Collections API authorised any project member to modify or destroy collection data regardless of roleGHSA-f49h-c5mr-5wmx published
Jul 23, 2026 by stuartcHigh -
Server-side request forgery through OAuth client endpoints, and unprivileged publishing of an instance-wide OAuth clientGHSA-677j-p2w8-mqpp published
Jul 23, 2026 by stuartcHigh -
Channel proxy leaks session cookies and credentials, forges internal requests, and reaches channels across project boundariesGHSA-2jxv-3v9h-wc75 published
Jul 23, 2026 by stuartcHigh -
Multiple authentication weaknesses in account-state enforcement, session and socket token revocation, second-factor gating and SSO identity validationGHSA-v6j6-x25r-jrgc published
Jul 23, 2026 by stuartcHigh -
OS command injection in Lightning adaptor metadata fetching (with adaptor-install and dashboard input-validation hardening)GHSA-55p9-h336-8jmx published
Jul 23, 2026 by stuartcCritical -
AI assistant authorization: a member of one project could read another project's assistant content and cause it to be sent to an external modelGHSA-6vh7-2h5q-6r94 published
Jul 23, 2026 by stuartcHigh -
Collaborative editor trusted the client for authorization, allowing cross-project data reads and viewer privilege escalationGHSA-pqh8-fgqc-x2xr published
Jul 23, 2026 by stuartcHigh -
Jobs could resolve another project's credential secrets at run timeGHSA-44jg-hwcc-7wvh published
Jul 23, 2026 by stuartcHigh
Learn more about advisories related to OpenFn/lightning in the GitHub Advisory Database