To report and discuss security vulnerabilities go to https://github.com/CommunitySolidServer/CommunitySolidServer/security/advisories
Security: CommunitySolidServer/CommunitySolidServer
Security
SECURITY.md
-
Unauthenticated authorization bypass of the /.internal/ storage guard via a double-slash path (//.internal/...), exposing password hashes and allowing internal-state tamperingGHSA-8xgx-32v4-xwjf published
Jul 27, 2026 by joachimvhCritical
Learn more about advisories related to CommunitySolidServer/CommunitySolidServer in the GitHub Advisory Database