THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4227-9989-jrhx (high) — Perses's missing authorization in datasource proxy allows cross-scope secret disclosure

[GHSA] GHSA-4227-9989-jrhx (high) — Perses's missing authorization in datasource proxy allows cross-scope secret disclosure

medgithub_advisoriesPublished 2026-09-18

GHSA-4227-9989-jrhx Severity: high CVE: CVE-2026-63199

Perses's missing authorization in datasource proxy allows cross-scope secret disclosure

### Impact

The datasource proxy authorizes the caller on the Datasource scope, then resolves and decrypts any Secret named in the request body with no Secret-scope check.

Datasource and Secret are distinct, independently grantable role scopes, so an ope

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4227-9989-jrhx