Kuma kuma-cp Default CORS Wildcard + LocalhostIsAdmin Admin Token Leakage
Security AdvisoryGHSA-3f59-x25m-578pMediumKuma
Affected:
- Kuma < 2.7.5
- Kuma >= 2.9.0, < 2.9.15
- Kuma >= 2.11.0, < 2.11.13
- Kuma >= 2.12.0, < 2.12.10
- Kuma >= 2.13.0, < 2.13.5
Fixed in:
- 2.7.25
- 2.9.15
- 2.11.13
- 2.12.10
- 2.13.5
Referenced CVEs: CVE-2026-18676 · 5.1 CVE-2026-45021
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.