VYPR

stump

by Stumpapp

CVEs (1)

  • CVE-2026-107450MedOct 8, 2026
    risk 0.35cvss 5.4epss —

    In Stump through 0.1.10, the updateSmartList and deleteSmartList GraphQL mutations (crates/graphql/src/mutation/smart_lists.rs) depend only on the shared AccessSmartList permission and resolve the target list at Reader access (lacking a creator check). Any authenticated user…