THREAT OPS › Threat News › [GHSA] GHSA-4227-9989-jrhx (high) — Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
[GHSA] GHSA-4227-9989-jrhx (high) — Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
GHSA-4227-9989-jrhx Severity: high CVE: CVE-2026-63199
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
### Impact
The datasource proxy authorizes the caller on the Datasource scope, then resolves and decrypts any Secret named in the request body with no Secret-scope check.
Datasource and Secret are distinct, independently grantable role scopes, so an ope
Indicators of compromise
- CVE-2026-63199cve
Original source: https://github.com/advisories/GHSA-4227-9989-jrhx