epa4all-client: Unauthenticated REST API for Patient Record Writes
Moderate severity
GitHub Reviewed
Published
May 19, 2026
in
oviva-ag/epa4all-client
•
Updated Jun 4, 2026
Package
Affected versions
<= 1.2.4
Patched versions
None
Description
Published by the National Vulnerability Database
May 26, 2026
Published to the GitHub Advisory Database
Jun 4, 2026
Reviewed
Jun 4, 2026
Last updated
Jun 4, 2026
Impact
Any network-reachable caller can write arbitrary documents to any patient's electronic
health record accessible by the institution's SMC-B card. In a misconfigured deployment
(e.g., following the production Docker example in the README), this is exploitable from
the local network without credentials.
Patches
Workarounds
Use network policies or proxies to enforce service-to-service authentication via e.g. mTLS.
References
Credits
Machine Spirits (contact@machinespirits.de)
References