THREATOPS
THREAT OPSThreat News › Plone security advisory 20260831

Plone security advisory 20260831

lowoss_secPublished 2026-08-31

<p>Posted by Maurits van Rees (Plone) on Aug 31</p>On behalf of the Plone/Zope Security Team I announce two vulnerability <br /> fixes in plone.restapi.<br /> <br /> * Unauthenticated Reflective Method Invocation via the REST API @search <br /> metadata_fields Parameter, <br /> <a href="https://github.com/plone/plone.restapi/security/advisories/GHSA-r3g9-vgf8-vv35" rel="nofollow">https://github.co

Original source: https://seclists.org/oss-sec/2026/q3/629