Security: profullstack/qryptchat-web
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Backup-PIN key derivation below OWASP standards allows offline brute force of backup keysGHSA-29hv-86qw-3vx5 published
Aug 16, 2026 by Noir0x63Moderate -
CoinPay OAuth callback links accounts by email without verifying email_verified (potential account takeover)GHSA-j2m4-m3w7-w2cq published
Aug 16, 2026 by Noir0x63High -
get_inactive_participants RPC returns full phone numbers of conversation participantsGHSA-ffpr-xfm2-pp84 published
Aug 16, 2026 by Noir0x63High -
Autoblog integration access tokens exposed in raw form in the /admin client bundleGHSA-75px-j56m-6cpr published
Aug 16, 2026 by Noir0x63Moderate -
SMS pumping and rate-limit evasion via direct Supabase Auth access with the public anon key and X-Real-IP spoofingGHSA-64m7-3h2w-2qr6 published
Aug 16, 2026 by Noir0x63Moderate -
Cross-user mass deletion: any participant can permanently destroy a whole direct conversation via /api/conversations/deleteGHSA-xm8x-rpr6-4j7h published
Aug 16, 2026 by Noir0x63Moderate -
Latent stored XSS in message rendering (dangerouslySetInnerHTML with raw content for non-plain formats)GHSA-9jq8-g7m8-wg4v published
Aug 16, 2026 by Noir0x63High -
Consolidated QryptChat Web security assessment: 37 vulnerabilities and 37 architectural deficienciesGHSA-3hqc-9v44-j37g published
Aug 16, 2026 by ralyodioHigh -
conversations table globally readable in code (RLS USING(true)); NOT exploitable in current productionGHSA-9jgr-3h36-9748 published
Aug 16, 2026 by ralyodioHigh -
Authenticated users can inject themselves as participants into arbitrary conversationsGHSA-vxcr-4mm8-jfm3 published
Aug 16, 2026 by Noir0x63High
Learn more about advisories related to profullstack/qryptchat-web in the GitHub Advisory Database