Security: getfider/fider
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Cross-Tenant Authentication Bypass via Missing tenant_id Filter in getVerificationByKeyGHSA-vxjw-gv4f-vq58 published
Jul 3, 2026 by mattwobertsCritical -
Server-Side Request Forgery (SSRF) via Webhook URLGHSA-g445-xwm7-594r published
Jul 3, 2026 by mattwobertsHigh -
Unsafe Markdown Rendering Leading to Potential Injection via Unfiltered URL SchemesGHSA-wm2w-gfh7-qg69 published
Jul 3, 2026 by mattwobertsModerate -
Authenticated arbitrary blob overwrite via client-controlled attachment bkey allows tenant logo replacementGHSA-vxp5-mf8m-grg9 published
Apr 28, 2026 by mattwobertsModerate