THREAT OPS › Threat News › [GHSA] GHSA-p23g-mvhj-jh3j (high) — GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
[GHSA] GHSA-p23g-mvhj-jh3j (high) — GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GHSA-p23g-mvhj-jh3j Severity: high CVE: CVE-2026-55178
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
### Summary
Multiple GeoLens read/link endpoints authorized only the resource named in the request URL (a map, a VRT, a source dataset, an AI request) and failed to re-authorize a **second, caller-in
Indicators of compromise
- CVE-2026-55178cve
- ghcr.iodomain
Original source: https://github.com/advisories/GHSA-p23g-mvhj-jh3j