PatchSiren

freedomofpress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW freedomofpress CVE published 2026-08-20

CVE-2026-49996

A vulnerability in SecureDrop Client, a desktop app for journalists to securely communicate with sources, allows a malicious SecureDrop Server to bypass securedrop-proxy's origin limitation via cross-origin redirects. This issue was fixed in version 1.3.1. The vulnerability impacts SecureDrop Client deployments, requiring defenders to verify their version and implement secure communication protocols to pr [truncated]