VYPR

stigmem-plugin-multi-tenant

by Eidetic Labs

CVEs (1)

  • CVE-2026-76236HigAug 19, 2026
    risk 0.40cvss epss

    stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, allowing deletion records to be written…