Skip to content

fix(security): Datasource authorization bypass through import and fork hidden datasource reuse (GHSA-p37g-mfwx-3r9f) - #42066

Merged
subrata71 merged 2 commits into
releasefrom
fix/ghsa-p37g
Jul 30, 2026
Merged

fix(security): Datasource authorization bypass through import and fork hidden datasource reuse (GHSA-p37g-mfwx-3r9f)#42066
subrata71 merged 2 commits into
releasefrom
fix/ghsa-p37g

Conversation

@appsmith-smithes

@appsmith-smithes appsmith-smithes Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Description

fix(security): Datasource authorization bypass through import and fork hidden datasource reuse (GHSA-p37g-mfwx-3r9f)

CE PR. The EE validation PR listed below already ran the full EE
suite, Cypress included, and came back green. Merge this CE PR first; the
hourly CE→EE sync then carries the fix into EE.

Vulnerability

Field Value
GHSA GHSA-p37g-mfwx-3r9f
CVE Not assigned
CVSS 8.1 (high)
CWE CWE-863
Affected component Datasource authorization bypass through import and fork hidden datasource reuse

Exposure Analysis

Fix

CE/EE sync

Merge this PR first. The hourly CE→EE sync propagates it to EE.

The linked EE validation PR is then refreshed from EE release and re-tested.

EE validation

EE validation PR: https://github.com/appsmithorg/appsmith-ee/pull/9393

EE CI status at the time this PR was opened: passing (ci-test|ci-test-limited, ci-test-result|ci-test-limited-result green).

Disclosure

Do not merge until advisory is ready for disclosure coordination.

After merge:

  1. Confirm fix is in release branch
  2. Coordinate with security team on disclosure timeline
  3. Update advisory with patched version and publish
  4. Notify reporter

Automation

/ok-to-test tags="@tag.All"

🔍 Cypress test results

Tip

🟢 🟢 🟢 All cypress tests have passed! 🎉 🎉 🎉
Workflow run: https://github.com/appsmithorg/appsmith/actions/runs/30476127335
Commit: ca50f01
Cypress dashboard.
Tags: @tag.All
Spec:


Wed, 29 Jul 2026 18:44:22 UTC

Communication

Should the DevRel and Marketing teams inform users about this change?

  • Yes
  • No

@appsmith-smithes appsmith-smithes Bot added Security Issues related to information security within the product ok-to-test Required label for CI labels Jul 29, 2026
@subrata71 subrata71 self-assigned this Jul 29, 2026
@appsmith-smithes
appsmith-smithes Bot marked this pull request as ready for review July 30, 2026 05:43
@appsmith-smithes
appsmith-smithes Bot requested a review from a team as a code owner July 30, 2026 05:44
@subrata71
subrata71 merged commit 62a5e53 into release Jul 30, 2026
88 of 91 checks passed
@subrata71
subrata71 deleted the fix/ghsa-p37g branch July 30, 2026 06:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Required label for CI Security Issues related to information security within the product

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant