THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p23g-mvhj-jh3j (high) — GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

[GHSA] GHSA-p23g-mvhj-jh3j (high) — GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

highgithub_advisoriesPublished 2026-08-18

GHSA-p23g-mvhj-jh3j Severity: high CVE: CVE-2026-55178

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

### Summary

Multiple GeoLens read/link endpoints authorized only the resource named in the request URL (a map, a VRT, a source dataset, an AI request) and failed to re-authorize a **second, caller-in

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p23g-mvhj-jh3j