PatchSiren

Chaskiq CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Chaskiq CVE published 2026-08-11

CVE-2026-72536

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. This could lead to unauthorized creation of payment intents and alteration of [truncated]

HIGH Chaskiq CVE published 2026-08-11

CVE-2026-72535

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:38.733Z and has not been modified since then. This CVE-2026-72535 details a missing authentication vulnerability in Chaskiq through commit 46dfdd1, allowing unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. [truncated]