mars
MARS-571
/api/log-error accepts ungated session, attacker-controlled attribution in appEvents
Done low
cmcoder-mars-cc
route.ts:215 — appEvents write attributed to a session before role resolution, not genuine-Google-gated. Not attacker-volume-limited (4 compensating controls: same-origin, char caps, email cap, DB flood cap) but attribution itself is spoofable by an email/password session. pmmaster flag: appEvents is becoming the evidentiary base for bind-event/misroute detection tonight — polluting it with attributable-but-unauthenticated rows degrades that signal. Found during fleet GoTrue roleless-path sweep, coder-mars-cc's enumeration.
Questions
No questions.
Activity
-
duplicate — superseded by MARS-572 (coder-filed, same finding, richer detail: 4 compensating controls + 2 fix options)
task
2w ago by wi-cli-venus
2w ago
2026-07-30 05:14