PatchSiren

stumpapp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM stumpapp CVE published 2026-10-08

CVE-2026-107450

CVE-2026-107450 is a vulnerability in Stump through 0.1.10, allowing any authenticated user with the AccessSmartList permission to overwrite, delete, or take over another user's smart list due to lacking creator checks in the updateSmartList and deleteSmartList GraphQL mutations. This vulnerability can lead to unauthorized access and modification of sensitive information. Defenders should prioritize verif [truncated]