THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rxhg-vcww-2mpw (low) — Fleet: ORDER BY column injection on activity list endpoints

[GHSA] GHSA-rxhg-vcww-2mpw (low) — Fleet: ORDER BY column injection on activity list endpoints

medgithub_advisoriesPublished 2026-08-20

GHSA-rxhg-vcww-2mpw Severity: low CVE: None

Fleet: ORDER BY column injection on activity list endpoints

### Summary

An authenticated user with read access to Activity could influence the `ORDER BY` clause of the activity list endpoints by supplying an arbitrary sort column:

- `GET /api/v1/fleet/activities` (`ListActivities`) - `GET /api/v1/fleet/hosts/{id}/activities` (`ListHostPastActivities`

Original source: https://github.com/advisories/GHSA-rxhg-vcww-2mpw