PatchSiren

The-Commit-Company CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM The-Commit-Company CVE published 2026-10-11

CVE-2026-108731

CVE-2026-108731 debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T12:19:38.912Z and has not been modified since then. The vulnerability is a missing authorization issue in Raven 2.0.0 through 3.0.0 that allows authenticated users to join invite-only Public workspaces by ignoring the can_only_join_via_invite setting. Attackers with the Raven User role can call the join [truncated]

MEDIUM The-Commit-Company CVE published 2026-10-11

CVE-2026-108730

CVE-2026-108730 is a missing authorization vulnerability in Raven 2.0.0 through 3.0.0 that allows authenticated non-members to read Public channel history and Open/Public channel file metadata across workspaces via legacy methods. Defenders should assess exposure and prioritize remediation, especially in systems using Raven 2.0.0 through 3.0.0, and verify workspace membership checks are properly enforced [truncated]