Security: eidetic-labs/stigmem
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)GHSA-x26h-xmv8-gxf7 published
Jun 19, 2026 by offbyonceHigh -
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)GHSA-xhv3-q4xx-349r published
Jun 19, 2026 by offbyonceHigh -
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)GHSA-6gqw-jqv7-v88m published
Jun 19, 2026 by offbyonceHigh -
Blind SSRF via unvalidated webhook subscription delivery_addressGHSA-5p3m-vhh6-9236 published
Jun 12, 2026 by offbyonceModerate -
Postgres schema identifier handling required defensive quotingGHSA-9pc9-4crj-mhpj published
May 19, 2026 by offbyonceHigh -
Unsigned plugin override could be enabled without a second explicit acknowledgmentGHSA-w7pm-9g55-mxfm published
May 19, 2026 by offbyonceHigh -
Federation peer registration lacked explicit out-of-band approvalGHSA-9vp8-3hmv-8fgh published
May 19, 2026 by offbyonceCritical -
Auth-disabled deployments may grant broad anonymous access outside loopbackGHSA-fp6w-8wpg-74g5 published
May 19, 2026 by offbyonceCritical -
Federation insecure transport settings may allow non-loopback cleartext federationGHSA-jmfc-hfjq-pxcp published
May 19, 2026 by offbyonceCritical -
Federation peer token timestamp validation may reject valid peer tokensGHSA-xh5j-xjfq-qvvx published
May 19, 2026 by offbyonceHigh