An authenticated non-admin project member can request the inplace-edit dialog for a raw custom_field_<id> project attribute and retrieve the stored comment text for an admin_only project custom field.
The normal project custom-field visibility and writable scopes exclude the field for the same user, but the dialog path resolves the custom field by raw id and renders the stored custom-field comment in read-only mode.
The claim is intentionally narrow: this discloses custom-field comment text only. This report does not claim hidden custom-field value disclosure, writes, or mutation.
An authenticated non-admin project member can request the inplace-edit dialog for a raw
custom_field_<id>project attribute and retrieve the stored comment text for anadmin_onlyproject custom field.The normal project custom-field visibility and writable scopes exclude the field for the same user, but the dialog path resolves the custom field by raw id and renders the stored custom-field comment in read-only mode.
The claim is intentionally narrow: this discloses custom-field comment text only. This report does not claim hidden custom-field value disclosure, writes, or mutation.