Security: koala73/worldmonitor
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Slack and Discord OAuth state consumption is non-atomic and fail-openGHSA-9m4c-824h-m4xw published
Aug 1, 2026 by koala73Moderate -
Generated API runtime validation is disabledGHSA-cmj5-cfhr-w964 published
Aug 1, 2026 by koala73Moderate -
MCP daily cost-cap bypass: quota slot refunded after the tool already executedGHSA-hcq5-jm84-2395 published
Jul 4, 2026 by koala73Moderate -
OAuth refresh-token reuse not contained: no family revocation on detected reuseGHSA-f6gj-3v7v-j75q published
Jul 4, 2026 by koala73Low -
Abuse-control / rate-limit bypass via spoofable cf-connecting-ip headerGHSA-c267-988w-7pq7 published
Jul 4, 2026 by koala73Moderate -
Windows command injection in Tauri open_url IPC (cmd /c start) — user-assisted desktop RCEGHSA-2x6r-qq54-mmhr published
Jul 4, 2026 by koala73High -
Unauthenticated cross-tenant read of all users' alert rules via public Convex query getByEnabledGHSA-r649-4cqj-w93h published
Jul 4, 2026 by koala73High -
Desktop trusted windows could read the full secret cache and local API tokenGHSA-5458-hq84-hcr5 published
Jul 24, 2026 by koala73High