Filtered by vendor Nasa-ammos Subscriptions
Filtered by product Plandev (sequencing-server) Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-71214 1 Nasa-ammos 1 Plandev (sequencing-server) 2026-08-10 9.8 Critical
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura.