CVE-2026-107841
Description
pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 0.9.6 - 0.10.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-3hj7-6vmj-h8v4ghsaADVISORY
- github.com/john-broadway/pacioli/commit/f3c7219f5dde6050bd7921e0ac55afd02771250cnvd
- github.com/john-broadway/pacioli/releases/tag/guard-v0.10.0nvd
- github.com/john-broadway/pacioli/security/advisories/GHSA-3hj7-6vmj-h8v4nvd
- nvd.nist.gov/vuln/detail/CVE-2026-107841ghsa
News mentions
0No linked articles in our index yet.