Security: ontola/atomic-server
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Stored XSS via uploaded files served inline (same-origin) on `/download` → account takeoverGHSA-x277-3wcg-g9r2 published
Jul 6, 2026 by joepioHigh -
Arbitrary file read via user-controlled `internalId` in the `/download` handler (leaks root agent private key)GHSA-8vc4-8hjq-988p published
Jul 6, 2026 by joepioHigh -
Unauthenticated `/setup` invite grants write access to the entire DriveGHSA-pfwx-xjp4-qxcj published
Jul 6, 2026 by joepioCritical -
Unauthenticated full-response SSRF in Atomic-Server /bookmark endpointGHSA-ff87-73jp-f3v4 published
Jul 6, 2026 by joepioHigh
Learn more about advisories related to ontola/atomic-server in the GitHub Advisory Database