Skip to content

Firefly III user API endpoints expose all users' information to any authenticated user (IDOR)

Moderate severity GitHub Reviewed Published Mar 6, 2026 in firefly-iii/firefly-iii

No open alerts for this advisory

Give feedback on Dependabot alerts