Security: getprobo/probo
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
OAuth2 consent bypass via unverified compliance-portal custom domainGHSA-4jp4-hf8m-xxhv published
Aug 18, 2026 by gearnodeHigh -
IsPublicIP SSRF guard missing IPv6 transition address checks allows agent tool SSRF via NAT64/6to4/TeredoGHSA-jq76-r8vw-9w36 published
Aug 18, 2026 by gearnodeModerate -
Open redirect bypass via path normalization: ASCII TAB survives path.Clean and collapses to a protocol-relative URL in browsersGHSA-p6m2-fv55-v5wp published
Aug 6, 2026 by gearnodeModerate -
Account takeover via OIDC login: the continue redirect hands the victim's root-session token to any unverified custom domainGHSA-r9mf-88r7-g6j9 published
Aug 6, 2026 by gearnodeHigh -
Broken access control in public e-signature API: any trust-center visitor can complete another visitor's NDA signature and inject audit-trail eventsGHSA-22xj-f767-ppw6 published
Jul 9, 2026 by SachaProboLow -
Unauthenticated cross-tenant and hidden-item disclosure via Query.node in the public Trust Center APIGHSA-w23w-f7v2-625w published
Jul 9, 2026 by SachaProboLow -
Stored XSS in the console via unsanitized Markdown (iframe srcdoc) in Organization Context; no CSP on the console appGHSA-9fx8-47w4-3vw8 published
Aug 18, 2026 by gearnodeModerate -
Vertical privilege escalation: an organization ADMIN can mint an OWNER membership via createUser, bypassing the owner-only set-owner authorization gateGHSA-cppp-g98f-gfpp published
Jul 9, 2026 by SachaProboHigh -
Cross-tenant IDOR via unvalidated FK referencesGHSA-c74x-79w6-63jh published
Jul 3, 2026 by gearnodeModerate -
GraphQL Alias-Based Application Layer Denial of Service (DoS)GHSA-prh2-g8pv-m7p9 published
Jul 3, 2026 by gearnodeModerate