THREAT OPS › Threat News › [GHSA] GHSA-cp3j-m783-3ph5 (high) — Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
[GHSA] GHSA-cp3j-m783-3ph5 (high) — Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
GHSA-cp3j-m783-3ph5 Severity: high CVE: CVE-2026-59185
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
## Summary
identrail's GitHub App connection-completion endpoint binds a fully client-supplied `installation_id` to the caller's workspace without verifying that the installation belongs to, or was instal
Indicators of compromise
- CVE-2026-59185cve
Original source: https://github.com/advisories/GHSA-cp3j-m783-3ph5