Critical severity9.8OSV Advisory· Published Feb 6, 2018· Updated Jun 17, 2026
CVE-2017-6199
CVE-2017-6199
Description
A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2v0.101, v0.102, v0.103, …+ 1 more
- (no CPE)range: v0.101, v0.102, v0.103, …
- (no CPE)range: <0.203
Patches
Vulnerability mechanics
References
4- github.com/sandstorm-io/sandstorm/commit/37bd9a7f4eb776cdc2d3615f0bfea1254b66f59dnvdPatchThird Party Advisory
- devco.re/blog/2018/01/26/Sandstorm-Security-Review-CVE-2017-6200-en/nvdExploitThird Party Advisory
- github.com/sandstorm-io/sandstorm/blob/v0.202/shell/packages/sandstorm-db/db.jsnvdThird Party Advisory
- sandstorm.io/news/2017-03-02-security-reviewnvdVendor Advisory
News mentions
0No linked articles in our index yet.