VYPR

goploy

by Zhenorzz

CVEs (1)

  • CVE-2026-53552criJul 7, 2026
    risk 0.59cvss epss

    ### Summary `Project.AddFile`, `Project.EditFile`, `Project.RemoveFile`, and `Project.Edit` in `cmd/server/api/project/handler.go` accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The…