THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cp3j-m783-3ph5 (high) — Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

[GHSA] GHSA-cp3j-m783-3ph5 (high) — Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

medgithub_advisoriesPublished 2026-09-09

GHSA-cp3j-m783-3ph5 Severity: high CVE: CVE-2026-59185

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

## Summary

identrail's GitHub App connection-completion endpoint binds a fully client-supplied `installation_id` to the caller's workspace without verifying that the installation belongs to, or was instal

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cp3j-m783-3ph5