THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p5vg-v7mj-f6q4 (high) — Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

[GHSA] GHSA-p5vg-v7mj-f6q4 (high) — Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

medgithub_advisoriesPublished 2026-09-18

GHSA-p5vg-v7mj-f6q4 Severity: high CVE: CVE-2026-81505

Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

## Summary frain-dev/convoy (all versions up to and including v26.6.2, no patch available) lets any authenticated caller who is authorized on at least one project read ANY OTHER project's "Source" record by ID via GET /api/v1/projects/{projectID}/sources/{sourceID} -

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p5vg-v7mj-f6q4