AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:56.157Z and has not been modified since then. Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact-change [truncated]
The CVE-2026-76238 record indicates a broken object level authorization vulnerability in stigmem versions before 0.9.0a12. This vulnerability exists in the decay sweep endpoint and allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tenants. The vulnerability can be exploited by submitting POST requests to the decay sweep endpoint with ttl_seconds [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:55.840Z and has not been modified since then. The stigmem-node package before version 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in its quarantine review endpoints. This issue affects multi-tenant deployments that use the stigmem-plugin-multi-ten [truncated]
The stigmem-node package before version 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in its RTBF (right-to-be-forgotten) tombstone mechanism. This issue is exploitable only in multi-tenant deployments that use the stigmem-plugin-multi-tenant. The flaw allows a tenant's deletion to be attributed to the wrong tenant and causes tombstone suppression to be applied tenant-blin [truncated]