{
  "schema_version": "1.0.0",
  "dataset": "security-research-library-resources",
  "as_of": "2026-10-04",
  "repository_url": "https://github.com/gkdataio/security-research-library",
  "scope": "Official defensive education and conceptual models; separate from qualifying award reports",
  "counts": {
    "resources": 129,
    "diagrams": 14
  },
  "taxonomy": {
    "schema_version": "1.0.0",
    "resource_types": [
      {
        "id": "security-standard",
        "title": "Security Standard"
      },
      {
        "id": "technical-standard",
        "title": "Technical Standard"
      },
      {
        "id": "implementation-guide",
        "title": "Implementation Guide"
      },
      {
        "id": "architecture-guide",
        "title": "Architecture Guide"
      },
      {
        "id": "reporting-guide",
        "title": "Reporting Guide"
      },
      {
        "id": "training-lab",
        "title": "Training Lab"
      },
      {
        "id": "research-paper",
        "title": "Research Paper"
      },
      {
        "id": "maintainer-advisory",
        "title": "Maintainer Advisory"
      }
    ],
    "topics": [
      {
        "id": "verification",
        "title": "Verification"
      },
      {
        "id": "identity",
        "title": "Identity"
      },
      {
        "id": "authorization",
        "title": "Authorization"
      },
      {
        "id": "ai-security",
        "title": "Ai Security"
      },
      {
        "id": "reporting",
        "title": "Reporting"
      },
      {
        "id": "web-foundations",
        "title": "Web Foundations"
      },
      {
        "id": "supply-chain",
        "title": "Software Supply Chain"
      },
      {
        "id": "cloud-security",
        "title": "Cloud Security"
      },
      {
        "id": "business-logic",
        "title": "Business Logic and State Integrity"
      },
      {
        "id": "memory-safety",
        "title": "Memory Safety and Process Isolation"
      },
      {
        "id": "interpreter-boundaries",
        "title": "Interpreter Boundaries"
      }
    ]
  },
  "skillset_definitions": [
    {
      "id": "authorization-modeling",
      "title": "Model access-control invariants",
      "defensive_objective": "Document expected actor, action, resource, and tenant relationships in an authorized design review"
    },
    {
      "id": "identity-lifecycle-review",
      "title": "Review identity lifecycle",
      "defensive_objective": "Assess binding, verification, recovery, linking, and revocation requirements using approved test accounts"
    },
    {
      "id": "approval-state-integrity",
      "title": "Review approval-state integrity",
      "defensive_objective": "Check that approval records bind to immutable content and survive state changes safely"
    },
    {
      "id": "concurrency-reasoning",
      "title": "Reason about concurrent state",
      "defensive_objective": "Model ordering assumptions and prove security invariants with local state-machine or unit tests"
    },
    {
      "id": "cloud-iam-review",
      "title": "Review cloud IAM boundaries",
      "defensive_objective": "Compare intended service authority with documented effective permissions and least-privilege requirements"
    },
    {
      "id": "integration-threat-modeling",
      "title": "Threat-model integrations",
      "defensive_objective": "Trace documented trust assumptions between services and identify where authorization responsibility changes"
    },
    {
      "id": "pipeline-trust-modeling",
      "title": "Model build and release trust",
      "defensive_objective": "Map trusted and untrusted inputs, artifacts, jobs, and identity boundaries in approved architecture diagrams"
    },
    {
      "id": "cache-artifact-isolation",
      "title": "Review artifact isolation",
      "defensive_objective": "Assess separation of caches and artifacts by trust level, and define integrity controls"
    },
    {
      "id": "dependency-provenance",
      "title": "Review dependency provenance",
      "defensive_objective": "Check explicit registries, namespace ownership, lockfiles, source pinning, and package-origin policy"
    },
    {
      "id": "machine-identity-governance",
      "title": "Review machine identities",
      "defensive_objective": "Document bot and service identity privileges, rotation, approvals, and separation of duties"
    },
    {
      "id": "secrets-containment",
      "title": "Review secrets containment",
      "defensive_objective": "Assess whether secrets are limited to the minimum necessary trusted execution contexts"
    },
    {
      "id": "untrusted-input-handling",
      "title": "Review input trust boundaries",
      "defensive_objective": "Assess validation and data/code separation without collecting offensive payloads"
    },
    {
      "id": "ai-authority-boundaries",
      "title": "Review AI authority boundaries",
      "defensive_objective": "Assess least privilege and independent validation at tool execution and data disclosure boundaries"
    },
    {
      "id": "secure-parser-review",
      "title": "Review parsing and serialization",
      "defensive_objective": "Reason about parser consistency, validation, and safe serialization contracts"
    },
    {
      "id": "browser-isolation-review",
      "title": "Review client isolation",
      "defensive_objective": "Study process, origin, memory-safety, and permission boundaries in patched historical cases"
    },
    {
      "id": "defensive-evidence-writing",
      "title": "Write bounded security evidence",
      "defensive_objective": "Separate demonstrated impact, modeled impact, remediation, and source uncertainty in review findings"
    },
    {
      "id": "encoding-invariant-review",
      "title": "Review text-encoding invariants",
      "defensive_objective": "Identify and document validation contracts at extension and parser boundaries, then verify them with safe unit tests"
    },
    {
      "id": "memory-safety-review",
      "title": "Review memory-safety assumptions",
      "defensive_objective": "Assess length, bounds, allocation, and lifetime assumptions in owned source code and vendor patches"
    },
    {
      "id": "patch-verification",
      "title": "Verify remediation evidence",
      "defensive_objective": "Compare vendor advisories, affected versions, fixes, and regression coverage without reproducing an exploit"
    },
    {
      "id": "security-token-design",
      "title": "Review security-token design",
      "defensive_objective": "Assess unpredictable generation, subject and operation binding, limited lifetime, single-use semantics and safe validation of security-sensitive tokens"
    },
    {
      "id": "error-response-design",
      "title": "Review secure error behavior",
      "defensive_objective": "Verify that failure responses minimize disclosure and that fallback paths preserve the original authorization context"
    }
  ],
  "resources": [
    {
      "schema_version": "1.0.0",
      "id": "angular-2026-host-binding-context-authority",
      "title": "Angular host bindings: bind sanitization to the concrete output element",
      "publisher": "Angular",
      "authors": [],
      "primary_url": "https://github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations"
      ],
      "skillset_ids": [
        "encoding-invariant-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-88057 concerns sanitization chosen from a directive's compile-time selector rather than the concrete element receiving its host binding. Composition and reuse could therefore apply an absent or weaker policy to a more sensitive browser sink. The maintainer confirms browser script-execution risk when an attacker controls the affected bound value; reviewed sources do not establish production compromise.",
      "defensive_use": "Treat element identity and output context as part of a binding's security contract. Re-evaluate that contract when composition, inheritance or dynamic construction changes the receiving element. The maintainer lists 22.1.0, 21.2.20 and 20.3.28 as patched; older end-of-support branches receive no patch. The researcher issue distinguishes ordinary URL, resource-loading and HTML contexts, so a generic URL filter is not evidence that all contexts are secured.",
      "prerequisites": [
        "Framework component composition and template binding concepts",
        "Basic browser output-context and sanitization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and linked primary discussion."
      },
      "dates": {
        "published": {
          "value": "2026-08-18",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Publication of the selected maintainer advisory; earlier public discussion is separately noted."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-08-18",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:31:08Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary pages read; publication dates are distinct from software release dates. No immutable resource edition established."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg",
          "title": "Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler",
          "publisher": "Angular",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:31:08Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "research",
          "url": "https://github.com/angular/angular/issues/69550",
          "title": "ResourceURL sanitizer bypass through host-binding selector mismatch",
          "publisher": "SkyZeroZx",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:31:08Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Exposure depends on attacker-influenced values reaching affected security-sensitive host bindings and a mismatch between compile-time and concrete-element context. Composition alone does not prove exploitability.",
        "SkyZeroZx published the linked issue on June 27, 2026; the advisory credits SkyZeroZx as Remediation developer, and alan-agius4, josephperrott and JeanMeche as Remediation reviewers. GitHub identifies alan-agius4 as the publishing account. The reviewed advisory has no explicit narrative byline, so authors is empty; publication and remediation credits do not by themselves establish who wrote the narrative. The August 18 date describes the selected maintainer publication, not the earliest public discussion or a product release.",
        "The maintainer suggests explicit sanitization or safe-scheme restriction as workarounds. Their applicability depends on the actual sink; the reviewed issue identifies stricter resource-loading and HTML contexts. This caveat is editorial defensive guidance, not a claim that the maintainer workaround was independently tested.",
        "The issue explains a minimal case but links its runnable reproduction elsewhere. No reproduction was run, and observed exploit outcomes are not independently established."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "angular-2026-raw-content-serialization-context",
      "title": "Angular SSR: preserve output context through serialization and post-processing",
      "publisher": "Angular",
      "authors": [
        "alan-agius4"
      ],
      "primary_url": "https://github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3v",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations"
      ],
      "skillset_ids": [
        "encoding-invariant-review",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "Angular's advisory for CVE-2026-69149 describes unsafe serialization of untrusted text in fallback raw-content containers. A server-generated DOM can lose its intended inert meaning when later serialization and parsing interpret that text as structure. The maintainer confirms same-origin script-execution risk; session theft is a possible application-dependent consequence, not a documented production compromise.",
      "defensive_use": "Model every serialization and reparse boundary, including HTML post-processing. The linked remediation discussion shows that preserving comment semantics matters alongside escaping. The original advisory lists 22.0.7, 21.2.19 and 20.3.27 as fixes. Later advisories identify additional node and fragment cases, so these historical minimums do not establish comprehensive current remediation.",
      "prerequisites": [
        "Server-side rendering and browser output-context concepts",
        "Basic trust-boundary and secure-input review"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and linked primary discussion."
      },
      "dates": {
        "published": {
          "value": "2026-07-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Publication of the selected maintainer advisory; earlier public discussion is separately noted."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-07-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:31:08Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary pages read; publication dates are distinct from software release dates. No immutable resource edition established."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3v",
          "title": "Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR",
          "publisher": "Angular",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:31:08Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "remediation",
          "url": "https://github.com/angular/domino/pull/32",
          "title": "fix: escape fallback raw-content text nodes",
          "publisher": "SkyZeroZx / Angular",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:31:08Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "fragment-followup",
          "url": "https://github.com/angular/angular/security/advisories/GHSA-v3p8-whq6-r5jg",
          "title": "SSR XSS via Unescaped template Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements",
          "publisher": "Angular",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:31:08Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "node-followup",
          "url": "https://github.com/angular/angular/security/advisories/GHSA-j3r3-mxqp-r2p4",
          "title": "SSR XSS via Unescaped Processing Instruction Nodes in Fallback Raw-Content Elements",
          "publisher": "Angular",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:31:08Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Exposure requires SSR and untrusted content in the affected rendering context. Ordinary Angular use alone does not establish exposure. Avoiding those bindings or the implicated post-processing path are scoped workarounds, not universal guarantees.",
        "SkyZeroZx authored the linked remediation proposal on June 22, 2026; maintainer alan-agius4 merged it July 7. These are public-discussion and merge dates, not resource-edition or product-release dates.",
        "The August 27 follow-ups describe separate processing-instruction and document-fragment reachability limits; they list 22.1.4, 21.2.22 and 20.3.30 as patched and older unsupported branches as unpatched. These follow-ups limit the original patch claim without asserting that every initial deployment reached every later case.",
        "The processing-instruction advisory requires programmatic construction, unlike ordinary template syntax; the fragment advisory includes ordinary text-node cases. Both provide minimal demonstrations, but no production victim evidence."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "apollo-2026-federation-router-subgraph-isolation",
      "title": "Apollo Federation: preserving the router-to-subgraph boundary",
      "publisher": "Apollo GraphQL",
      "authors": [
        "David Walter"
      ],
      "primary_url": "https://www.apollographql.com/blog/securing-apollo-federation-subgraphs-context-and-best-practices",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "Explains the deployment assumption behind centralized GraphQL federation controls: internal subgraphs accept traffic only through the router. Federation coordination remains available even when ordinary client introspection is disabled. Consequently, hiding schema discovery cannot establish the service boundary on which router-enforced authorization, demand controls and operation restrictions depend.",
      "defensive_use": "For an owned federated design, document router and subgraph responsibilities. Require network isolation and authenticated router-to-subgraph communication, retain entry-point authorization, and review resource limits and schema-change permissions as separate controls.",
      "prerequisites": [
        "GraphQL federation architecture",
        "Service authentication and network isolation concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public article readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-01-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publication date displayed above the article title."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-01-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publication date displayed above the article title."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T05:19:50Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed the dated vendor article and its explicit author byline; no immutable revision was established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.apollographql.com/blog/securing-apollo-federation-subgraphs-context-and-best-practices",
          "title": "Securing Apollo Federation Subgraphs: Context and Best Practices",
          "publisher": "Apollo GraphQL",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:19:50Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Vendor architecture guidance, not a disclosed product vulnerability or evidence about a particular deployment.",
        "Disabling ordinary introspection does not replace subgraph isolation.",
        "Prerequisites and the review exercise are editorial guidance."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "arxiv-2026-cache-key-precision-and-capacity",
      "title": "Web cache key precision and capacity isolation",
      "publisher": "arXiv",
      "authors": [
        "Matteo Golinelli",
        "Kaan Onarlioglu",
        "Bruno Crispo"
      ],
      "primary_url": "https://arxiv.org/abs/2608.04744",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "cache-artifact-isolation",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "version": "arXiv:2608.04744v1",
      "summary": "This author-submitted study connects unnecessary cache-key variation with redundant object storage, reduced cache effectiveness and increased origin load. It treats cache-key design as an application availability boundary, rather than a performance-only setting.",
      "defensive_use": "Document which request properties genuinely distinguish representations, and review key definitions against that application contract. Compare precise keying with deduplication overhead and the legitimate-traffic costs of rate limiting or anomaly detection; preserve meaningful response distinctions when simplifying keys.",
      "prerequisites": [
        "HTTP request and response semantics",
        "Reverse-proxy and origin-server architecture"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Primary article readable without login."
      },
      "dates": {
        "published": {
          "value": "2026-08-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "First arXiv submission, not a confirmed peer-reviewed publication date."
        },
        "version_released": {
          "value": "2026-08-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Version 1 submission history."
        },
        "source_displayed": {
          "value": "2026-08-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Submission date displayed on the abstract page."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:59:12Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed the abstract, version history and full-text limitations, mitigations and CDN discussion. No accompanying tools were retrieved or run."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://arxiv.org/abs/2608.04744",
          "title": "Web Cache Overflow: Exploiting Imprecise Keys for Cache Degradation and Beyond",
          "publisher": "arXiv",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:59:12Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "paper",
          "url": "https://arxiv.org/html/2608.04744v1",
          "title": "Author-submitted version 1 full text",
          "publisher": "arXiv",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:59:12Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "Preprint; the reviewed pages do not establish peer review.",
        "Experiments concern stand-alone caching proxies. CDN applicability was not experimentally demonstrated and is explicitly limited by the authors.",
        "Results depend on capacity, object sizes and workload; they do not establish present exposure of any deployment.",
        "This record omits operational methods and grants no testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "astro-2026-composable-dispatch-origin-enforcement",
      "title": "Astro: composable dispatch must preserve mandatory origin checks",
      "publisher": "Astro",
      "authors": [
        "matthewp"
      ],
      "primary_url": "https://github.com/withastro/astro/security/advisories/GHSA-8mv7-9c27-98vc",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "The maintainer describes origin enforcement attached to optional middleware while independently composed dispatchers could invoke application handlers first. The resulting cross-site request forgery can change state using browser credentials but cannot read cross-origin responses. Conceptual failure: a security setting did not guarantee enforcement along every path to a protected operation.",
      "defensive_use": "The advisory identifies 7.0.5 as patched, moving equivalent checks to dispatch boundaries so composition order cannot remove them. Editorial lesson: review mandatory controls as invariants of each protected operation, not assumptions about wrapper ordering. Local regression coverage should establish that composition changes preserve rejection before side effects.",
      "prerequisites": [
        "Server-rendered applications and framework composition",
        "Trust-boundary modeling and application authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-07-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        },
        "source_displayed": {
          "value": "2026-07-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No educational-resource edition established; software patch chronology is separate."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:39:32Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory read. No live testing or independent patch execution performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-8mv7-9c27-98vc",
          "title": "composable astro/hono pipeline bypasses security.checkOrigin when middleware() is absent or misordered",
          "publisher": "Astro",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:39:32Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "CVE-2026-73423. Applicability requires the composable astro/hono pipeline with omitted or late middleware; the default pipeline is excluded.",
        "The affected-version field says at least 7.0.0 without an upper bound, while the patch field names 7.0.5. Preserve that source inconsistency. matthewp published the advisory; jlgore is credited as reporter.",
        "Exact patch-release date was not established. Actual business consequences depend on application handlers; production exploitation is not established.",
        "No bounty or production compromise is established. Learning prerequisites and generalized defensive reasoning are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "astro-2026-route-normalization-authorization-consistency",
      "title": "Astro: routing and authorization must agree on resource identity",
      "publisher": "Astro",
      "authors": [
        "matthewp"
      ],
      "primary_url": "https://github.com/withastro/astro/security/advisories/GHSA-376h-93r7-7g6f",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "Astro's base-path removal accepted a textual prefix without establishing a complete path segment. Routing and authorization middleware could consequently disagree about the requested resource. The maintainer bounds the authorization bypass to applications with a non-root base and pathname-based middleware protection; it is not a claim that every Astro application lacks authorization.",
      "defensive_use": "The maintainer identifies 7.2.4 as patched, and its release notes confirm segment-aware base handling. Editorial lesson: a permission decision must bind to the same canonical resource that execution resolves. Review normalization contracts between middleware and routing, and preserve resource-level checks when public path representations change.",
      "prerequisites": [
        "URL path normalization and framework routing",
        "Middleware authorization and canonical resource identity"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-08-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition established."
        },
        "source_displayed": {
          "value": "2026-08-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:19:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory and release notes read. No live testing or independent patch execution."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/withastro/astro/security/advisories/GHSA-376h-93r7-7g6f",
          "title": "Authorization bypass from missing path-segment boundary check when stripping the configured base",
          "publisher": "Astro",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:18:30Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/withastro/astro/releases/tag/astro@7.2.4",
          "title": "astro@7.2.4 release",
          "publisher": "Astro",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:18:52Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "CVE-2026-84376. matthewp published the advisory; Ryoga-exe is credited as reporter. The affected range is astro through 7.2.3.",
        "The software release page displays August 19 without a year in retrieved text. A full patch-release date is therefore not asserted; it is distinct from advisory publication and resource-edition chronology.",
        "No production compromise or individual bounty is established. Learning prerequisites and generalized review guidance are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "authentik-2026-source-mapping-mutation-authority",
      "title": "authentik: source-mapping edits carry identity-rebinding authority",
      "publisher": "authentik",
      "authors": [
        "rissson"
      ],
      "primary_url": "https://github.com/goauthentik/authentik/security/advisories/GHSA-wr38-7xg8-fqxr",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-49443 concerns writable identity-mapping fields in API serializers. Delegated connection-management authority could alter which local user or group a source identity represented. The maintainer reports victim-account authentication; its example addresses user mappings, while the impact statement also covers groups.",
      "defensive_use": "Editorial reasoning: permission to maintain an integration object does not establish permission to reassign the identity it authenticates. Treat identity bindings as security-sensitive relationships, restrict writable fields, and separately authorize any supported reassignment. The advisory lists patched versions 2025.12.6, 2026.2.4 and 2026.5.1.",
      "prerequisites": [
        "Identity-provider integration and authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-05-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-05-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational edition date established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:39:39Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary source reviewed; no independent reproduction or deployment assessment."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/goauthentik/authentik/security/advisories/GHSA-wr38-7xg8-fqxr",
          "title": "UserSourceConnection.user and GroupSourceConnection.group are changeable through the API",
          "publisher": "authentik",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:39:39Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        }
      ],
      "caveats": [
        "The described user case requires both an account at a configured identity source and delegated permission to add or change source connections. Ordinary authentication alone is insufficient.",
        "rissson published the maintainer advisory; no separate reporter is identified. Group consequences are described more broadly than the user-focused example; no independent reproduction is claimed.",
        "Patch release dates are not established by the advisory. Publication and educational edition metadata must not substitute for software chronology. No individual award is established."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "authlib-2026-error-path-redirect-authority",
      "title": "Authlib: error responses must preserve redirect-destination validation",
      "publisher": "Authlib",
      "authors": [],
      "primary_url": "https://github.com/authlib/authlib/security/advisories/GHSA-r95x-qfjj-fjj2",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-44681 describes an OIDC error path selecting a response destination before client and destination validation. The maintainer reports an unauthorized browser redirect, explicitly excluding direct disclosure of authorization codes or tokens. The failed boundary was untrusted request data becoming trusted error-response routing.",
      "defensive_use": "Editorial reasoning: an exception can exercise authority even when the main operation fails. Establish destination trust before producing redirect-capable errors, and review rejection paths across grant implementations. The official v1.6.12 release notes corroborate the validation correction.",
      "prerequisites": [
        "Identity-provider integration and authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-05-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-05-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational edition date established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:39:39Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary source reviewed; no independent reproduction or deployment assessment."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/authlib/authlib/security/advisories/GHSA-r95x-qfjj-fjj2",
          "title": "Open Redirect in Authlib OIDC Implicit/Hybrid Authorization",
          "publisher": "Authlib",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:39:39Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/authlib/authlib/releases/tag/v1.6.12",
          "title": "Release v1.6.12",
          "publisher": "Authlib",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:39:39Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "Exposure requires an affected server supporting implicit or hybrid OIDC grants; the advisory excludes code-only configurations from this variant. Authentication is unnecessary, but browser redirection requires user interaction. Phishing consequences are possible downstream harm, not demonstrated account compromise.",
        "The advisory identifies 1.6.12 and 1.7.1 as patched. Software versions are not resource editions; exact patch-release dates remain unrecorded.",
        "azmeuk published the advisory; y011d4 is credited as Reporter. The reviewed advisory has no explicit narrative byline, so authors is empty; publication and reporting credits do not by themselves establish who wrote the narrative. No bounty qualification or independent reproduction is established."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "aws-iam-machine-identity-best-practices",
      "title": "AWS IAM security best practices for workload identities",
      "publisher": "Amazon Web Services",
      "authors": [],
      "primary_url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "cloud-security",
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "cloud-iam-review",
        "machine-identity-governance",
        "identity-lifecycle-review",
        "secrets-containment"
      ],
      "version": null,
      "summary": "Use this guide to review machine identity design: favor short-lived role credentials for workloads, limit permissions to required actions and resources, and retire unnecessary access. It also explains policy validation, access reviews, and organizational guardrails that help keep workload access aligned with its purpose.",
      "defensive_use": "Compare an owned workload’s documented identity lifecycle and minimum permission needs with the guide, recording unnecessary access for review.",
      "prerequisites": [
        "Basic understanding of cloud workloads, roles, and identity policies",
        "Familiarity with authentication versus authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official documentation was publicly readable at review time; implementation services can have separate costs."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T15:32:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Living guidance checked on the verification date; no numerical release or documented update date claimed"
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html",
          "title": "Temporary workload credentials, least privilege, access cleanup, policy validation, and permissions guardrails",
          "publisher": "Amazon Web Services",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T15:32:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "AWS-managed policies may need further narrowing for a specific workload.",
        "Organization-level guardrails constrain permissions; they do not grant access by themselves."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "axios-2026-streamed-upload-budget-enforcement",
      "title": "Axios: enforce upload budgets across transport implementations",
      "publisher": "Axios",
      "authors": [
        "jasonsaayman"
      ],
      "primary_url": "https://github.com/axios/axios/security/advisories/GHSA-mwf2-3pr3-8698",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "version": null,
      "summary": "CVE-2026-68948 documents a transport-contract mismatch: an application configured an outbound body limit, but the HTTP/2 stream path delegated to a transport that did not enforce it. The maintainer-published report describes local observation of transmission beyond that budget. Bandwidth, quota and availability consequences are application-dependent; the advisory excludes code execution, credential disclosure and destination control.",
      "defensive_use": "The maintainer identifies 1.18.0 as patched. Review byte-budget enforcement as an invariant shared by transport adapters. The merged remediation describes consistent upload/content limits and regression coverage. Editorial lesson: enforce limits during consumption of unknown-length input and ensure failure cancels downstream work; configuration metadata alone is not enforcement.",
      "prerequisites": [
        "HTTP transport adapters and streamed request bodies",
        "Resource budgets and failure propagation"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and remediation references readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-07-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established; software patch chronology is retained in the caveats."
        },
        "source_displayed": {
          "value": "2026-07-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed beside the advisory publisher."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:39:01Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed maintainer advisory, release and merged remediation discussion; no vulnerability reproduction or independent patch testing performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-mwf2-3pr3-8698",
          "title": "HTTP/2 streamed uploads bypass maxBodyLength",
          "publisher": "Axios",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:39:01Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/axios/axios/releases/tag/v1.18.0",
          "title": "Axios v1.18.0 release",
          "publisher": "Axios",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:39:01Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        },
        {
          "id": "remediation",
          "url": "https://github.com/axios/axios/pull/11000",
          "title": "Merged request hardening and stream-limit changes",
          "publisher": "Axios",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:39:01Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Exposure requires untrusted stream influence, the Node HTTP adapter using HTTP/2, and a finite configured body limit. Buffered bodies and browser adapters are excluded from this advisory.",
        "The advisory credits asadeddin as reporter; jasonsaayman is the publishing maintainer, not an inferred discoverer.",
        "The advisory retains old prose saying no fixed release exists, while its patched-version metadata identifies 1.18.0 and the dated release corroborates stream-limit hardening. These distinct source states are preserved.",
        "No production incident, measured billing loss or bounty amount was established. Learning prerequisites and generalized design advice are editorial.",
        "The cited software release is dated 2026-06-13; it is distinct from the advisory publication and is not a claim about the latest available release.",
        "The advisory lists affected versions as >=1.13.0 and patched versions as >=1.18.0; its affected-range metadata lacks an upper bound. These overlapping published fields do not establish that patched releases remain vulnerable."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "better-auth-2026-authorization-code-consumption-integrity",
      "title": "Better Auth: single-use authorization requires atomic state consumption",
      "publisher": "Better Auth",
      "authors": [],
      "primary_url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-7w99-5wm4-3g79",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "security-token-design",
        "approval-state-integrity",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary sources readable without an account."
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:19:04Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed primary disclosure and maintainer corroboration; no independent vulnerability reproduction performed."
      },
      "content_scope": "defensive_education",
      "summary": "The maintainer disclosure for CVE-2026-53518 identifies separated reading and deletion of a single-use OAuth authorization record. Under concurrent processing, multiple successful consumers could receive independent token sets. The established impact is duplicate authority within the original approved scope, not expansion of that scope.",
      "defensive_use": "Model consuming a grant as one indivisible state transition, including across service replicas and storage adapters. A successful read must not itself authorize issuance. Maintainer release 1.6.11 adds atomic consumption and corroborates the OAuth fix; review adapter guarantees rather than relying on process-local serialization.",
      "prerequisites": [
        "OAuth authorization-code and token lifecycle concepts",
        "Atomic database transitions and concurrent request handling"
      ],
      "dates": {
        "published": {
          "value": "2026-05-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Release page displays May 12 without a year in retrieved text; exact patch-release date not established."
        },
        "source_displayed": {
          "value": "2026-05-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication, distinct from patch availability."
        }
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-7w99-5wm4-3g79",
          "title": "@better-auth/oauth-provider: Parallel requests can reuse one authorization code",
          "publisher": "Better Auth",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:19:04Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "title": "Release v1.6.11",
          "publisher": "Better Auth",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:19:04Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "Requires an affected OAuth/OIDC provider deployment and a redeemable authorization code; the source does not establish bypass of code possession or PKCE.",
        "Maintainer-reported behavior, not evidence of production compromise. The advisory covers @better-auth/oauth-provider 1.6.0 before 1.6.11 and specified legacy plugins; an effective external atomic single-use control changes exposure.",
        "The source credits chdanielmueller as reporter; no advisory author byline is established.",
        "This is a substantive maintainer disclosure corroborated by release notes, not an independently peer-reviewed paper or an award-backed record."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "better-auth-2026-local-account-linking-verification",
      "title": "Better Auth: incoming identity proof does not validate existing credentials",
      "publisher": "Better Auth",
      "authors": [
        "gustavovalverde"
      ],
      "primary_url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-g38m-r43w-p2q7",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-53516 concerns implicit linking to an unverified local account. Provider-side email verification was allowed to confer legitimacy on previously stored local credentials. The resulting merged identity could retain an unauthorized password-based login even when ordinary email verification was required.",
      "defensive_use": "Editorial reasoning: linking combines authorities, so prove ownership on both sides before merging credentials. Requiring verification only after the merge cannot establish who created the earlier password. Release 1.6.11 corroborates a verified-local-email gate; the advisory also identifies 1.7.0-beta.4 as patched. Disabling implicit linking is a documented interim control.",
      "prerequisites": [
        "OAuth identity-provider claims and local account-linking concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-05-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-05-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource edition date established; software remediation is recorded separately."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:39:59.794959Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and release notes reviewed; no independent reproduction or deployment assessment."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-g38m-r43w-p2q7",
          "title": "better-auth: OAuth sign-in can link to an account an attacker registered in advance",
          "publisher": "Better Auth",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:39:59.794959Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/better-auth/better-auth/releases/tag/v1.6.11",
          "title": "Release v1.6.11",
          "publisher": "Better Auth",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:39:59.794959Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        }
      ],
      "caveats": [
        "Exposure requires email/password sign-in, OAuth or SSO, implicit linking, and an existing unverified local account before the legitimate federated sign-in. Impact is account access, not compromise of the identity provider.",
        "The advisory lists stable versions below 1.6.11 and 1.7.0-beta.0 through beta.3. Its deprecated compatibility opt-out restores weaker linking behavior.",
        "gustavovalverde published the advisory; avrmeduard is credited as reporter. Release notes show May 12 without an explicit year in retrieved text; exact patch date is left unestablished.",
        "Maintainer disclosure, not a peer-reviewed paper, award-backed report, or evidence of production exploitation."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "better-auth-2026-scim-ownerless-provider-authority",
      "title": "Better Auth SCIM: absent ownership must not grant shared authority",
      "publisher": "Better Auth",
      "authors": [
        "gustavovalverde"
      ],
      "primary_url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-j8v8-g9cx-5qf4",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "Personal SCIM providers could lack an owner, while management checks rejected mismatched ownership only when an owner existed. Missing identity binding therefore admitted unrelated authenticated users. The maintainer reports provider disclosure, deletion and token replacement, with provisioning authority limited to enabled SCIM features.",
      "defensive_use": "Editorial reasoning: an unknown owner is a separate authorization state, not an implicit shared resource. Review creation, migration and subsequent management together. The fix mandates owner binding and makes legacy ownerless records fail closed; administrators must resolve those records rather than assuming a package upgrade assigns legitimate ownership.",
      "prerequisites": [
        "SCIM provisioning, bearer-token authority and object ownership concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-05-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-05-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T16:32:15Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary source reviewed; no independent reproduction or deployment assessment."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/better-auth/better-auth/security/advisories/GHSA-j8v8-g9cx-5qf4",
          "title": "SCIM personal-provider ownership advisory",
          "publisher": "Better Auth",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T16:31:53Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        },
        {
          "id": "bulletin",
          "url": "https://better-auth.com/blog/security-update-june-2026",
          "title": "Security update: June 2026",
          "publisher": "Better Auth",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T16:19:37Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "Exposure concerns ownerless personal SCIM providers in applications with multiple signed-in users. Ownership enforcement is disabled by default, but enabling it later does not protect pre-existing ownerless providers; those require separate remediation. Organization-bound providers use membership and role checks. Affected versions are 1.5.0 through 1.7.0-beta.3.",
        "The advisory identifies fixes in 1.7.0-beta.4 and 1.7.0; the 1.6.x line requires mitigation. The June 2, 2026 vendor bulletin independently identifies the SCIM-specific beta fix, rather than treating its general stable-release guidance as sufficient.",
        "gustavovalverde published the notice; Jvr2022 is credited as reporter. Impact is maintainer-reported; compromise of a deployed instance is not established. Patch-release dates remain unverified and are not resource-edition dates."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "bugsink-2026-token-expiry-unit-integrity",
      "title": "Bugsink: time-unit consistency in account-access token expiry",
      "publisher": "Bugsink",
      "authors": [
        "vanschelven"
      ],
      "primary_url": "https://github.com/bugsink/bugsink/security/advisories/GHSA-4f45-qmjf-82cv",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "security-token-design",
        "patch-verification"
      ],
      "version": null,
      "summary": "GHSA-4f45-qmjf-82cv describes account-access links whose configured seconds were interpreted as days. The maintainer reports unused email-verification, password-reset and new-user setup tokens surviving their intended lifetime.",
      "defensive_use": "Editorial lesson: represent security durations with explicit units and verify expiration independently of single-use behavior. The maintainer lists versions before 2.5.1 as affected and identifies 2.5.1 as correcting the unit conversion and removing over-age tokens before acceptance.",
      "prerequisites": [
        "Basic server-side identity and authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-08-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established. Software patch-release date 2026-08-31 is distinct from resource publication."
        },
        "source_displayed": {
          "value": "2026-08-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T10:29:18Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory and release notes reviewed. Deployment state and source immutability are not established."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/bugsink/bugsink/security/advisories/GHSA-4f45-qmjf-82cv",
          "title": "Email verification, password-reset, and new-user setup links remain valid beyond their configured lifetime",
          "publisher": "Bugsink",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:29:18Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release-notes",
          "url": "https://github.com/bugsink/bugsink/blob/main/CHANGELOG.md",
          "title": "Bugsink changelog: 2.5.1",
          "publisher": "Bugsink",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:29:18Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires possession of an unused token; the advisory says random tokens are not practically guessable. Access remains within the associated account’s permissions, without adding team or project memberships. Successful use deletes the token.",
        "The source describes possible unauthorized login after expiry, not a documented production compromise or observed theft. The fix is maintainer-reported; this review did not independently assess deployments or session cleanup.",
        "vanschelven published the advisory; no separate reporter is named. The original report date is unknown. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "chrome-bfcache-restored-session-state",
      "title": "Chrome bfcache: restored pages and session-state boundaries",
      "publisher": "Google Chrome for Developers",
      "authors": [
        "Barry Pollard"
      ],
      "primary_url": "https://developer.chrome.com/docs/web-platform/bfcache-ccns",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "web-foundations",
        "identity"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "identity-lifecycle-review"
      ],
      "version": null,
      "prerequisites": [
        "Browser origin and navigation concepts",
        "HTTP session and response-cache fundamentals"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official documentation readable without an account at review time."
      },
      "content_scope": "defensive_education",
      "summary": "Explains Chrome’s conditional admission of no-store pages to the back/forward cache. A restored page resumes in-memory document state rather than performing a fresh network load. The guide describes eviction safeguards around authentication changes and recommends considering data refresh on restoration.",
      "defensive_use": "Distinguish HTTP cache policy from suspended-page lifetime in an owned application’s session model. Define how sensitive state is cleared or refreshed after restoration and how logout remains effective across navigation. Preserve server-side authorization independently of restored client state.",
      "dates": {
        "published": {
          "value": "2024-10-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Explicit article publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2025-09-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Explicit last-updated date; not a new publication or browser release date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T05:39:10Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the Chrome guidance and the linked web.dev restoration section. Relevant to 2026 session design, but the article’s dated rollout statement is not fresh rollout telemetry."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://developer.chrome.com/docs/web-platform/bfcache-ccns",
          "title": "Enabling bfcache for Cache-Control: no-store",
          "publisher": "Google Chrome for Developers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:39:10Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "restoration-guide",
          "url": "https://web.dev/articles/bfcache",
          "title": "Back/forward cache",
          "publisher": "Google web.dev",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:39:10Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Chrome-specific eligibility safeguards must not be generalized to every browser or authentication design.",
        "The broader web.dev guide still describes the Chrome change as ongoing; the separately dated Chrome article provides more specific implementation context.",
        "No browser execution or live application assessment was performed; this is lifecycle guidance, not an individual vulnerability report."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "chrome-document-isolation-policy-boundaries",
      "title": "Document Isolation Policy: process separation and residual authority",
      "publisher": "Google Chrome for Developers",
      "authors": [
        "Camille Lamy"
      ],
      "primary_url": "https://developer.chrome.com/blog/document-isolation-policy",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "web-foundations",
        "memory-safety"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "integration-threat-modeling",
        "secrets-containment"
      ],
      "version": null,
      "summary": "Explains per-document cross-origin isolation as a response to process-level information exposure that logical origin checks alone cannot prevent. Document Isolation Policy allows independently isolated frames while preserving popup communication. Subresource policy either requires explicit sharing permission or removes credentials from relevant cross-origin requests.",
      "defensive_use": "Editorial lesson: separate process confidentiality, resource delivery and application authority in architecture reviews. Isolation does not remove same-origin storage access or asynchronous messaging, so these channels retain their own authorization requirements. Evaluate isolation choices against required embedded-resource and sign-in behavior.",
      "prerequisites": [
        "Browser origins, frames, HTTP resource policies and process isolation"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public first-party guidance."
      },
      "dates": {
        "published": {
          "value": "2025-05-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "guide",
          "note": "Historical publication relevant to 2026 architecture review."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Chrome 137 is a software version, not an educational edition."
        },
        "source_displayed": {
          "value": "2025-05-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "guide",
          "note": "Displayed last-updated date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:38:43Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Dated first-party guide reviewed; current browser coverage was not independently established."
      },
      "sources": [
        {
          "id": "guide",
          "url": "https://developer.chrome.com/blog/document-isolation-policy",
          "title": "Document Isolation Policy: Enable powerful web features with ease",
          "publisher": "Google Chrome for Developers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:38:43Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Architectural guidance, not an individual vulnerability disclosure or evidence of deployed compromise. Security benefits are the publisher's design claims.",
        "The article establishes desktop availability from Chrome 137; its Android rollout intention is not confirmation of present support. Verify relevant browser support separately.",
        "Isolated and non-isolated same-origin frames lose synchronous DOM access but retain asynchronous communication and storage sharing. This is not general tenant isolation."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "chrome-local-network-permission-boundaries",
      "title": "Chrome Local Network Access: separate browser reachability from site authority",
      "publisher": "Google Chrome for Developers",
      "authors": [
        "Chris Thompson"
      ],
      "primary_url": "https://developer.chrome.com/blog/local-network-access",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "web-foundations"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "integration-threat-modeling",
        "authorization-modeling"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary-source guidance."
      },
      "content_scope": "defensive_education",
      "summary": "Chrome's design addresses websites using the browser's network position to reach local devices without a separate user decision. A secure-context permission gate reduces local-device CSRF and network fingerprinting. The 2026 Chrome 145 release refines the boundary by separating local-network permission from loopback permission.",
      "defensive_use": "Editorial lesson: distinguish a website's origin, the browser's network reachability and the user's intended destination class. Document which local integration actually needs permission and preserve a usable denial path. Treat the grant as permission to connect, not proof of application-level authorization. Review local-device authentication separately.",
      "prerequisites": [
        "Browser origins, secure contexts and network address spaces"
      ],
      "dates": {
        "published": {
          "value": "2025-06-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "guide",
          "note": "Historical guide with a separately dated September 2025 launch update."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Browser milestones are implementation chronology, not resource editions."
        },
        "source_displayed": {
          "value": "2025-09-29",
          "precision": "day",
          "basis": "explicit",
          "source_id": "guide",
          "note": "Explicit inline update; the footer still displays 2025-06-09."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T17:29:30Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Original guide and Chrome 142/145 documentation reviewed earlier; Chrome 147 coverage clarification added after fresh release-note review. No live behavior was tested."
      },
      "sources": [
        {
          "id": "guide",
          "url": "https://developer.chrome.com/blog/local-network-access",
          "title": "New permission prompt for Local Network Access",
          "publisher": "Google Chrome for Developers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:20:45Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "chrome-142",
          "url": "https://developer.chrome.com/release-notes/142",
          "title": "Chrome 142",
          "publisher": "Google Chrome for Developers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:20:45Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "chrome-145",
          "url": "https://developer.chrome.com/release-notes/145",
          "title": "Chrome 145",
          "publisher": "Google Chrome for Developers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:20:45Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "chrome-147",
          "url": "https://developer.chrome.com/release-notes/147",
          "title": "Chrome 147: Local Network Access",
          "publisher": "Google Chrome for Developers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T17:29:30Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "The guide describes an evolving rollout and replaces the earlier Private Network Access preflight approach. Its initial transport limitations are historical, not a verified inventory of current gaps.",
        "Chrome 142 release notes identify an October 28, 2025 stable release and include local-to-loopback requests, beyond the original guide’s first-milestone scope. Chrome 145 notes identify February 10, 2026 and separate local and loopback permissions while retaining the older permission name as an alias.",
        "Chrome 147 release notes, last updated April 7, 2026, document permission gating for WebSockets and WebTransport and extend service-worker navigation coverage to subframes. Those notes expressly exclude main-frame navigations; permission coverage must not be generalized to every browser request.",
        "This is architectural guidance rather than a vulnerability or award report. Browser-wide implementation parity and current enterprise-policy coverage were not established."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "chromium-rule-of-two-input-isolation",
      "title": "Chromium Rule of Two: input trust, memory safety and privilege",
      "publisher": "Chromium Project",
      "authors": [],
      "primary_url": "https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/rule-of-2.md",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "memory-safety",
        "verification"
      ],
      "skillset_ids": [
        "memory-safety-review",
        "secure-parser-review",
        "browser-isolation-review",
        "untrusted-input-handling"
      ],
      "version": null,
      "summary": "An architecture policy for avoiding the combination of untrusted input, memory-unsafe implementation and high privilege. It explains safer parsing, privilege separation and careful review of unsafe code behind safe interfaces.",
      "defensive_use": "For an owned component, map input origin, language guarantees and execution privilege. Keep semantic authorization separate from successful parsing.",
      "prerequisites": [
        "Basic understanding of parsing, process privileges and memory lifetime"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official source-tree documentation is publicly readable."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T17:52:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Current HEAD documentation reviewed; no original publication or last-update date inferred."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/rule-of-2.md",
          "title": "The Rule Of 2",
          "publisher": "Chromium Project",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T17:52:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Memory safety does not establish data trust or permission to perform an operation.",
        "Chromium-specific exceptions are not blanket guarantees for other projects."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "coder-2026-provisioned-object-ownership-integrity",
      "title": "Coder: privileged provisioning must preserve existing object ownership",
      "publisher": "Coder",
      "authors": [
        "jdomeracki-coder"
      ],
      "primary_url": "https://github.com/coder/coder/security/advisories/GHSA-9rjw-3gwp-f59v",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "prerequisites": [
        "Basic understanding of server-side object authorization and resource ownership"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:10:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary disclosure and maintainer evidence reviewed; no deployment inspection or vulnerability testing performed."
      },
      "content_scope": "defensive_education",
      "dates": {
        "published": {
          "value": "2026-06-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "source_displayed": {
          "value": "2026-06-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource edition is stated; software fix chronology is recorded in caveats."
        }
      },
      "summary": "CVE-2026-55429 concerns a provisioning update-or-insert operation that could change an existing workspace application’s ownership relationship without checking the existing workspace. The maintainer describes potential redirection of subsequent application traffic across workspace boundaries under elevated provisioning authority.",
      "defensive_use": "Editorial lesson: privileged service execution is not evidence that every referenced object belongs to the initiating workspace. Enforce ownership invariants at the mutation boundary, including collision/update behavior. The maintainer patch rejects cross-workspace reassignment while preserving legitimate same-workspace rebuilds and initial claims of unowned objects.",
      "caveats": [
        "The maintainer requires elevated access as a template author or external provisioner operator. The stated consequence is application-traffic redirection, including IDE or terminal sessions; no customer incident, measured data loss, or independent reproduction is established here.",
        "The advisory credits Anthropic’s Security Team for independent disclosure (ANT-2026-22441); the listed author is the advisory publisher account.",
        "The advisory lists patched software versions 2.34.2, 2.33.8, 2.32.7, and 2.29.17 and no workaround. Release v2.34.2 independently links this fix. Pull request 26103 merged June 11, 2026; this merge date is not a resource edition date or a deployment date.",
        "The maintainer pull request describes regression coverage for ownership transitions, including same-workspace rebuilds and unowned object claims. This review did not execute those tests or establish that any installation is upgraded. No award evidence is supplied."
      ],
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/coder/coder/security/advisories/GHSA-9rjw-3gwp-f59v",
          "title": "Workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID",
          "publisher": "Coder",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-patch",
          "url": "https://github.com/coder/coder/pull/26103",
          "title": "Prevent cross-tenant workspace app rebinding",
          "publisher": "Coder",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/coder/coder/releases/tag/v2.34.2",
          "title": "v2.34.2 security release",
          "publisher": "Coder",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "dify-2026-tracing-configuration-tenant-authority",
      "title": "Dify: telemetry destination changes carry tenant data-disclosure authority",
      "publisher": "Zafran Labs",
      "authors": [
        "Ido Shani",
        "Gal Zaban"
      ],
      "primary_url": "https://www.zafran.io/resources/difytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-apps",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "ai-security",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "ai-authority-boundaries",
        "patch-verification",
        "integration-threat-modeling"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary-source disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": "Displayed publication date of the primary educational source; not software patch timing."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned educational edition established."
        },
        "source_displayed": {
          "value": "2026-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": "Displayed publication date of the primary educational source; not software patch timing."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:59:14Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Public primary sources reviewed; no software execution or deployment testing."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://www.zafran.io/resources/difytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-apps",
          "title": "DifyTap research",
          "publisher": "Zafran Labs",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:59:14Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "fix",
          "url": "https://github.com/langgenius/dify/pull/35793",
          "title": "Tenant-scoping fix for tracing configuration",
          "publisher": "Dify",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:59:14Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/langgenius/dify/releases/tag/1.14.2",
          "title": "Dify v1.14.2 release notes",
          "publisher": "Dify",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:59:14Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "content_scope": "defensive_education",
      "summary": "Zafran’s tracing case, CVE-2026-41947, explains that console authentication did not bind configuration changes to the application’s tenant. Traces contain prompts and responses, so changing telemetry routing also changes their recipients. The researcher reports cross-tenant configuration control and resulting disclosure; the merged maintainer fix corroborates the missing tenant restriction.",
      "defensive_use": "The merged fix resolves applications under the authenticated tenant before tracing operations and returns the same denial as an absent application. It covers configuration and tracing handlers and later adds cross-tenant regression coverage. Editorial lesson: treat observability configuration as data-export authority, with authorization independent of ordinary application-client access.",
      "prerequisites": [
        "Tenant-scoped object authorization",
        "AI telemetry flows and external data recipients"
      ],
      "caveats": [
        "The detailed research requires a console account and an application identifier. Its introductory unauthenticated framing must not replace these stated prerequisites. Application-client access is not administration permission.",
        "The researcher’s article covers four findings; this resource covers only tracing authorization. No production victim, exposure count or individual award is established.",
        "The fix merged May 14, 2026. Official v1.14.2 notes include it; the researcher dates that software release May 19, 2026 and discusses v1.15.0 as the broader four-finding remediation. These are not educational-edition dates.",
        "The research timeline also places an April 2025 last-report publication before its December 2025 first report, and lists a June 25 release after its displayed June 22 publication. Those inconsistent dates are not silently repaired.",
        "No regression tests were executed in this review. Public disclosure grants no testing authorization."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "directus-2026-preauthorization-side-effect-integrity",
      "title": "Directus: denied mutations must leave dependent state unchanged",
      "publisher": "Directus",
      "authors": [
        "br41nslug"
      ],
      "primary_url": "https://github.com/directus/directus/security/advisories/GHSA-p623-wgx3-wxp8",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "approval-state-integrity",
        "patch-verification"
      ],
      "version": null,
      "prerequisites": [
        "Basic server-side authorization and persistent-state concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary disclosure readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-08-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-08-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T12:29:14Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and maintainer remediation evidence reviewed; no target testing or deployment verification performed."
      },
      "content_scope": "defensive_education",
      "summary": "GHSA-p623-wgx3-wxp8 describes service overrides committing cleanup before their superclass checked permission. Rejected mutations could therefore disconnect automation links, remove attribution metadata or invalidate permission caches. A denial response did not mean that the operation left application state unchanged.",
      "defensive_use": "Editorial lesson: include cleanup, cache invalidation and relationship changes in the authorization boundary, and assess state preservation on rejected operations. The maintainer says 12.1.0 moves access checks before side effects or defers effects until an authorized mutation succeeds. PR 27800 independently corroborates the ordering correction.",
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/directus/directus/security/advisories/GHSA-p623-wgx3-wxp8",
          "title": "Directus pre-authorization side effects advisory",
          "publisher": "Directus",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:29:14Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "patch",
          "url": "https://github.com/directus/directus/pull/27800",
          "title": "Fix side effects in service overrides",
          "publisher": "Directus",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:29:14Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/directus/directus/releases/tag/v12.1.0",
          "title": "Directus v12.1.0 release",
          "publisher": "Directus",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:29:14Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The maintainer lists versions before 12.1.0 as affected. The automation impact requires knowledge of the affected flow identifier; the advisory describes anonymous as well as unauthorized callers.",
        "The advisory reports state changes, not a production incident. It explicitly excludes content disclosure and privilege elevation; impact is confined to availability, cached state and specified attribution fields.",
        "Published August 5, 2026 by br41nslug; tr4ce-ju is credited as reporter. PR 27800 merged July 1, 2026. The release page displays July 1 and includes that fix; its rendered timestamp omits the year, so the review does not independently assert a full software release date.",
        "The advisory identifies 12.1.0 as patched but does not establish restoration of previously lost state. No in-application workaround is supplied. The resource edition date remains unknown; software chronology is recorded separately."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "django-2026-query-alias-structure-boundary",
      "title": "Django: ORM alias metadata must not acquire query authority",
      "publisher": "Django Software Foundation",
      "authors": [
        "Jacob Walls"
      ],
      "primary_url": "https://www.djangoproject.com/weblog/2026/feb/03/security-releases/",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification",
        "interpreter-boundaries"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and official release documentation."
      },
      "dates": {
        "published": {
          "value": "2026-02-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication, separate from software remediation chronology."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established; software patch releases are described in defensive_use."
        },
        "source_displayed": {
          "value": "2026-02-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit primary advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T09:09:13Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and release documentation reviewed. No reproduction, live-target access, or independent patch testing."
      },
      "content_scope": "defensive_education",
      "summary": "Django confirms CVE-2026-1312: application-controlled column aliases could cross from metadata into SQL structure when used across relation filtering and ordering. Exploitability requires an application to admit untrusted alias definitions into that ORM workflow; using Django alone does not establish exposure. The advisory establishes potential SQL injection, not observed production compromise.",
      "defensive_use": "The official announcement identifies repaired releases 6.0.2, 5.2.11 and 4.2.28, issued February 3, 2026; release notes independently corroborate the 6.0.2 fix. Editorial lesson: distinguish query values from identifiers and structural metadata, constrain each according to its role, and preserve that contract when composing ORM features.",
      "prerequisites": [
        "ORM query composition and the distinction between bound values and SQL identifiers",
        "Tracing application-controlled metadata across library interfaces"
      ],
      "sources": [
        {
          "id": "advisory",
          "url": "https://www.djangoproject.com/weblog/2026/feb/03/security-releases/",
          "title": "Django security releases issued: 6.0.2, 5.2.11, and 4.2.28",
          "publisher": "Django Software Foundation",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:09:13Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://docs.djangoproject.com/en/dev/releases/6.0.2/",
          "title": "Django 6.0.2 release notes",
          "publisher": "Django Software Foundation",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:09:13Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Solomon Kebede is the credited reporter; Jacob Walls authored the announcement. No bounty amount is established.",
        "This resource covers CVE-2026-1312 only. Other issues in the same multi-issue announcement are not merged into its impact.",
        "The reviewed announcement lists supported branches; it does not establish the status of every unsupported release.",
        "No specific application data loss or universal remote exposure is demonstrated by the reviewed sources. Learning prerequisites and generalized design guidance are editorial."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "dolibarr-2026-portal-object-authorization",
      "title": "Dolibarr portal accounts: credential writes need object authorization",
      "publisher": "CodeAnt AI",
      "authors": [
        "Amartya Jha"
      ],
      "primary_url": "https://codeant.ai/security-research/cve-2026-71505-dolibarr-bola-enables-portal-account-takeover",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "Research on CVE-2026-71505 describes inconsistent authorization between reading and modifying company portal accounts. A role-level check did not establish authority over the particular company. In researcher-owned fixtures, the omission enabled account takeover, invoice access and disclosure of stored password verifiers.",
      "defensive_use": "Apply actor-to-object checks consistently to every credential mutation. The linked maintainer patch adds resource checks to account creation, update and deletion; the CNA identifies versions before 24.0.0 as affected. Editorially, keep credential changes explicitly permissioned and sensitive verifiers out of responses.",
      "prerequisites": [
        "Basic authentication and access-control concepts",
        "Familiarity with application trust boundaries"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-08-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-08-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T06:19:33Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary sources reviewed; no immutable article revision established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://codeant.ai/security-research/cve-2026-71505-dolibarr-bola-enables-portal-account-takeover",
          "title": "CVE-2026-71505: Dolibarr BOLA Enables Portal Account Takeover",
          "publisher": "CodeAnt AI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:19:33Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "cna",
          "url": "https://www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-third-party-write-route",
          "title": "Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route",
          "publisher": "VulnCheck",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:19:33Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "maintainer-patch",
          "url": "https://github.com/Dolibarr/dolibarr/commit/4cf305ebb958eeffa921aad7c94de179b764f7e7",
          "title": "Fix prevent edit by external users - reported by VulnCheck",
          "publisher": "Dolibarr",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:19:33Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "An authenticated principal with third-party creation rights is required. The researcher's demonstrated fixture also held read-companies rights, although the article identifies creation rights as sufficient for the vulnerable write.",
        "Observed evidence comes from a local development build with fixture companies, not customer accounts. Disclosed password hashes were not shown cracked.",
        "The researcher lists CVSS 8.1; the CNA gives CVSS v4 7.1. Scores are preserved as different source claims, not reconciled.",
        "Article publication (August 23) and CNA publication (August 24, 2026) are distinct. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "dompurify-2026-cross-realm-sanitization-consistency",
      "title": "DOMPurify: accepted DOM realms must retain complete sanitization",
      "publisher": "DOMPurify / Cure53",
      "authors": [],
      "primary_url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "interpreter-boundaries"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-49458 describes a mismatch between accepting DOM objects from another realm and recognizing them during later sanitization. Checks tied to local constructor identity could omit protective decisions and subtree traversal. The general lesson is that admitting an input representation also commits the implementation to enforcing every required security check for that representation.",
      "defensive_use": "Compare the set of accepted representations with the set covered by every protective decision, including nested content. Treat an unrecognized representation as an explicit policy decision rather than silently skipping validation. Review remediation and regression coverage together. These are conceptual review objectives, not a claim that any specific proposed implementation was shipped or independently tested.",
      "prerequisites": [
        "JavaScript realm and DOM object concepts",
        "Sanitization, nested content and browser activation boundaries"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and official release evidence."
      },
      "dates": {
        "published": {
          "value": "2026-05-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Publication of the selected advisory."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition is established."
        },
        "source_displayed": {
          "value": "2026-05-26",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T17:55:25Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and official release sources read. Review does not establish current exposure or independently reproduce the behavior."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8",
          "title": "Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound instanceof checks",
          "publisher": "DOMPurify / Cure53",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T17:52:49Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/cure53/DOMPurify/releases/tag/3.4.6",
          "title": "DOMPurify 3.4.6",
          "publisher": "DOMPurify / Cure53",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T17:52:49Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release-metadata",
          "url": "https://api.github.com/repos/cure53/DOMPurify/releases/tags/3.4.6",
          "title": "Official DOMPurify 3.4.6 release metadata",
          "publisher": "DOMPurify / Cure53 via GitHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T17:54:37Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "The advisory requires attacker-influenced DOM from another same-origin realm, in-place sanitization and subsequent consumer activation. It excludes ordinary string input and same-realm in-place use from this issue.",
        "It reports script execution with Chromium 148 and DOMPurify 3.4.5. Production compromise, account takeover and independent reproduction are not established here.",
        "The advisory lists versions through 3.4.5 as affected and 3.4.6 as patched. This historical minimum is not a comprehensive current security guarantee.",
        "The official 3.4.6 release describes stronger cross-realm and shadow-DOM checks plus expanded regression coverage. Its metadata records May 26, 2026 at 13:04:11 UTC; that software-release time is separate from the unknown resource-edition date. Advisory suggestions are not evidence of exact shipped implementation.",
        "The advisory credits offset as Reporter. cure53 is the publishing account, not an explicit article byline, so authors remains empty. Release-wide thanks to offset and Bankde do not establish both as reporters of this particular advisory."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "filebrowser-2026-share-owner-permission-lifecycle",
      "title": "File Browser: existing shares must follow current owner permissions",
      "publisher": "File Browser",
      "authors": [
        "hacdias"
      ],
      "primary_url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-v9w4-gm2x-6rvf",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification",
        "identity-lifecycle-review"
      ],
      "version": null,
      "summary": "GHSA-v9w4-gm2x-6rvf describes public file-sharing authority outliving its owner's permissions. Creating a share required sharing and download rights, but subsequent public access did not revalidate those rights. The maintainer-published report describes continued file retrieval after revocation in version 2.62.2.",
      "defensive_use": "Editorial lesson: permission changes must constrain previously issued capabilities, not only new capability creation. The merged remediation checks the owner's current sharing and download permissions during public access. Its pull-request description records separate regression cases for revoking either permission. Model issuance and later use as distinct authorization decisions.",
      "prerequisites": [
        "Basic server-side authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-04-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-04-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T10:50:10Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and linked remediation evidence reviewed; deployment status was not assessed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-v9w4-gm2x-6rvf",
          "title": "Share links remain accessible after Share/Download permissions are revoked",
          "publisher": "File Browser",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:50:10Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "fix",
          "url": "https://github.com/filebrowser/filebrowser/pull/5888",
          "title": "Pull request 5888: share-owner permission revalidation",
          "publisher": "File Browser",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:50:10Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires an existing share and access to its link, followed by revocation of the owner's relevant permissions. This is a source-reported demonstration, not independently reproduced here; no production exposure is established.",
        "CVE-2026-35604. The advisory lists versions through 2.62.2 as affected and 2.63.1 as patched; it does not resolve the intervening-version gap. Pull request 5888 was merged April 4, 2026; that merge date is not a verified package-release date.",
        "Published by hacdias; Koda Reef (kodareef5) is credited as reporter and authored the remediation pull request. Resource edition is unspecified. The repository displayed an August 31, 2026 archive notice at review."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "formie-2026-integration-settings-credential-authority",
      "title": "Formie: integration settings need operation and attribute authority",
      "publisher": "Verbb / Formie",
      "authors": [],
      "primary_url": "https://github.com/verbb/formie/security/advisories/GHSA-v3f3-cmj4-cvj9",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "secrets-containment",
        "patch-verification"
      ],
      "version": null,
      "summary": "Formie's advisory describes two coupled authority failures: an integration-settings operation lacked sufficient permission checks, and broad settings mutation could change the destination used with stored credentials. The maintainer reports credential disclosure and server-side requests whose responses were returned to the caller. The distinct lesson is to constrain both who may invoke an operation and which security-sensitive attributes it may change.",
      "defensive_use": "The two branch-specific patches require control-panel request context, a valid form and integration permission, then limit mutable settings while excluding destination and credential properties. Editorial lesson: operation authorization and attribute authority are complementary controls; possessing an authenticated session does not establish either. Review alternate entry points after a shared permission repair. The official releases identify 2.2.23 for Craft 4 and 3.1.31 for Craft 5 as patched.",
      "prerequisites": [
        "Distinguishing authentication from operation-specific authorization",
        "Understanding settings mutation and credential-bearing integration requests"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "The advisory, patches and release evidence are publicly readable."
      },
      "dates": {
        "published": {
          "value": "2026-07-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer publication; separate from the later database entry."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition date established."
        },
        "source_displayed": {
          "value": "2026-07-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed by the maintainer advisory."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T22:13:40Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory, both patches, database chronology and official release metadata reviewed. This was source review, not reproduction or a deployment assessment."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/verbb/formie/security/advisories/GHSA-v3f3-cmj4-cvj9",
          "title": "Formie integration-settings security advisory",
          "publisher": "Verbb / Formie",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T22:12:53Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "advisory-database",
          "url": "https://github.com/advisories/GHSA-v3f3-cmj4-cvj9",
          "title": "GitHub Advisory Database entry for CVE-2026-76086",
          "publisher": "GitHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T22:12:14Z",
          "supports": [
            "dates",
            "version"
          ]
        },
        {
          "id": "craft4-patch",
          "url": "https://github.com/verbb/formie/commit/6735fe4ae8f6a2a76930716ad7876b236f7c530d",
          "title": "Formie Craft 4 integration authorization and settings restriction patch",
          "publisher": "Verbb / Formie",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T22:12:43Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "craft5-patch",
          "url": "https://github.com/verbb/formie/commit/dde7799dfa7e4d0a11e28754ad8544dba62d5def",
          "title": "Formie Craft 5 integration authorization and settings restriction patch",
          "publisher": "Verbb / Formie",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T22:12:43Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "craft4-release",
          "url": "https://api.github.com/repos/verbb/formie/releases/tags/2.2.23",
          "title": "Official Formie 2.2.23 release metadata",
          "publisher": "Verbb / Formie",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T22:12:43Z",
          "supports": [
            "version",
            "dates"
          ]
        },
        {
          "id": "craft5-release",
          "url": "https://api.github.com/repos/verbb/formie/releases/tags/3.1.31",
          "title": "Official Formie 3.1.31 release metadata",
          "publisher": "Verbb / Formie",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T22:12:43Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The described case requires an affected installation and an authenticated caller, including a front-end member; credential impact additionally depends on a configured integration holding credentials.",
        "The advisory identifies incomplete earlier authorization remediation. Temporary restrictions on registration and control-panel access are not a complete configuration-only fix.",
        "The reviewed sources provide no controlled test transcript, production incident, victim count or independent reproduction. Downstream account takeover or cloud compromise is not established. No individual award is established.",
        "The advisory body credits Jorge González as reporter; its formal credit lists Pig-Tail as Finder. Their identity relationship is not established here. engram-design is the publishing account, not an explicit narrative byline, so authors remains empty.",
        "The GitHub database records its own publication and review on September 23, 2026. The official release APIs give July 9, 2026 at 12:21:35 UTC for 2.2.23 and 12:26:02 UTC for 3.1.31. Software release, advisory publication, database entry, educational edition and installation-specific deployment are separate events; deployment dates remain unknown."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "frappe-2026-linked-document-response-authorization",
      "title": "Frappe: linked data must preserve document and field permissions",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Man Yue Mo"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2026-012_Frappe/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-39351 concerns related-document expansion in a REST response. Frappe loaded linked records without checking the caller’s permission and serialized them without field filtering. The research identifies disclosure of otherwise inaccessible documents in tested version 15.96.0.",
      "defensive_use": "Editorial lesson: authorization on a parent object cannot authorize every object reachable from it. Define response contracts that preserve both per-document access and field visibility during expansion. The maintainer advisory identifies patched releases 15.104.0 and 16.14.0; it does not describe the patch implementation.",
      "prerequisites": [
        "Basic API access-control concepts",
        "Familiarity with server-side data processing"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-04-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-04-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:10:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary research and maintainer evidence reviewed. Article immutability and deployment remediation were not established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2026-012_Frappe/",
          "title": "GHSL-2026-012: Unauthorized Data Exposure via REST API Link Expansion in Frappe - CVE-2026-39351",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-advisory",
          "url": "https://github.com/frappe/frappe/security/advisories/GHSA-8ggw-hfr6-rw3x",
          "title": "Unrestricted Doctype access via API exploit",
          "publisher": "Frappe",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires a readable parent document whose expanded links reach records the caller cannot otherwise access; it does not establish unrestricted access to every document.",
        "The publication explains the code-level disclosure mechanism but supplies no customer incident or measured data-loss evidence. Do not infer write access or account takeover.",
        "Reported January 19, 2026; maintainer advisory published April 7; detailed research published April 24. Fix-release dates were not established by the reviewed sources.",
        "The byline is Man Yue Mo. Discovery is credited to GitHub Security Lab Taskflow Agent, with human review by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "github-2026-internal-metadata-authority",
      "title": "GitHub internal metadata: preserve the boundary between user data and service authority",
      "publisher": "Wiz Research",
      "authors": [
        "Sagi Tzadik"
      ],
      "primary_url": "https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations",
        "cloud-security"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "secure-parser-review",
        "untrusted-input-handling",
        "defensive-evidence-writing",
        "patch-verification"
      ],
      "version": null,
      "summary": "Wiz's CVE-2026-3854 research examines a data-to-authority boundary in GitHub's backend. User-controlled operation metadata reached downstream services as trusted configuration. Code execution was demonstrated on Enterprise Server and hosted infrastructure. Wiz bounded cross-tenant content validation to its own accounts; broader repository exposure was a capability inference, not demonstrated theft of customer content.",
      "defensive_use": "Editorial lessons: preserve provenance when internal services exchange mixed-trust data, keep policy decisions independent of user-controlled metadata, and remove environment-inappropriate execution paths. GitHub confirms input sanitization and removal of unnecessary code paths as remediation. Review the vendor's maintained release guidance rather than treating a researcher version table as definitive.",
      "prerequisites": [
        "Familiarity with service-to-service trust boundaries",
        "Basic authorization and serialization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public researcher and vendor articles readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-04-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": "Researcher article publication and public disclosure."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No immutable article revision is identified; this field is not a product patch date."
        },
        "source_displayed": {
          "value": "2026-04-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T06:29:29Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Researcher and vendor accounts reviewed. This is historical educational evidence, not a finding that a current deployment is vulnerable."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854",
          "title": "Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)",
          "publisher": "Wiz Research",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:28:56Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "vendor",
          "url": "https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/",
          "title": "Securing the git push pipeline: Responding to a critical remote code execution vulnerability",
          "publisher": "GitHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:29:29Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Technical precondition: an authenticated user needed repository push permission (vendor). Learning prerequisites above are editorial.",
        "Wiz reports controlled cross-tenant validation with its own accounts and says it did not access other tenants' repository contents. GitHub's investigation attributes observed activity to the researchers and reports no customer-data access, modification or exfiltration.",
        "Wiz dates reporting and hosted remediation to March 4, 2026, Enterprise Server patch release to March 10, and disclosure to April 28. GitHub corroborates hosted remediation on March 4; its article was updated April 29.",
        "Remediation-version disagreement: Wiz lists 3.19.3 among fixed versions, while GitHub's updated guidance recommends 3.19.4 or later and newer patch levels across other branches. The difference is preserved rather than resolved by inference; no independent patch verification was performed.",
        "The exact award amount and payment settlement are undisclosed in the reviewed articles. This educational resource does not qualify or promote the existing award-report candidate."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-aip-151-operation-completion-integrity",
      "title": "Google long-running operations: cancellation requests and completion evidence",
      "publisher": "Google",
      "authors": [],
      "primary_url": "https://google.aip.dev/151",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "business-logic",
        "web-foundations"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "integration-threat-modeling",
        "error-response-design"
      ],
      "version": null,
      "summary": "Google's approved long-running-operation guidance separates failures before work starts from failures during execution. Its linked Operation contract distinguishes best-effort cancellation, terminal outcomes and deletion of the tracking resource. Work may finish despite a cancellation request; a returned wait response can still describe pending work.",
      "defensive_use": "Editorial synthesis: keep client intent, control acknowledgements, terminal operation evidence and business effects separate. An application should not mark an action reversed or release a reserved entitlement merely because cancellation was requested. Define the service-specific evidence needed to reconcile the outcome and any already-committed effects.",
      "prerequisites": [
        "Basic asynchronous API and application state-machine concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "The official AIP and linked first-party operation contract were readable without sign-in."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication was not established. The Created header does not establish publication of the current text."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately dated educational edition was established."
        },
        "source_displayed": {
          "value": "2025-02-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Newest displayed changelog entry, not publication or latest repository modification. The page's Created and Updated headers both show 2019-07-25."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T12:14:17Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Official AIP, pinned operation contract and first-party error-guidance change reviewed. Maintained guidance without a numbered edition; the review date does not make it newly published guidance."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://google.aip.dev/151",
          "title": "AIP-151: Long-running operations",
          "publisher": "Google",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T12:11:47Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "operation-contract",
          "url": "https://github.com/googleapis/googleapis/blob/1b141494162fee2993345d056cf709ebf1d0402c/google/longrunning/operations.proto",
          "title": "Google long-running operation contract at reviewed revision",
          "publisher": "Google",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T12:12:35Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "error-guidance-change",
          "url": "https://github.com/aip-dev/google.aip.dev/commit/5209e64b26c564e020690273a1b9fd09e6598e9d",
          "title": "AIP-151 error-propagation clarification commit",
          "publisher": "Google AIP project",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T12:14:09Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The linked contract says successful cancellation retains the operation with a CANCELLED error. Deleting the operation expresses disinterest in its result and does not cancel execution.",
        "The done field marks completion, not success; the outcome can be failure or cancellation. Some services may omit result data, so missing results must not be treated as proof of success.",
        "Neither reviewed source guarantees rollback of prior effects or specifies a universal authorization policy for reading, cancelling or deleting operations. Authorization is therefore not assigned as a topic.",
        "The 2025-02-04 changelog entry was committed on 2025-02-07. These maintenance signals and the 2019-07-25 page headers are distinct from publication or edition-release dates.",
        "These are Google API contracts and design guidance, not universal asynchronous-API guarantees, an implementation audit, vulnerability claim, bounty evidence or testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-aip-155-request-identity-contract",
      "title": "Google API request identity: bind retry semantics to the logical operation",
      "publisher": "Google",
      "authors": [],
      "primary_url": "https://google.aip.dev/155",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "business-logic",
        "web-foundations"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "Google's Approved request-identification guidance makes supplied IDs an idempotency contract with service-defined retention. Duplicates should receive the prior success response; a documented exception permits current resource state. AWS's supporting article discusses caller-scoped identity, consistent response meaning, coordinated identity/effect recording and rejection of changed intent.",
      "defensive_use": "Editorial synthesis: distinguish who may act, which logical operation is being repeated and what state was committed. Document identity scope, retention assumptions and response meaning. A request ID does not confer authority. Preventing duplicate effects does not guarantee eventual success or establish end-to-end exactly-once delivery. Keep each integration's completion and authorization responsibilities explicit.",
      "prerequisites": [
        "Basic familiarity with API requests, distributed failures and application state transitions"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official API guidance and supporting architecture article."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The page's Created field does not establish publication of its current text."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No dated educational-resource edition is established for this living guidance."
        },
        "source_displayed": {
          "value": "2024-01-08",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Newest displayed AIP-155 Changelog entry; not publication, an edition release or the corresponding commit date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T09:43:28Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the Approved AIP, its first-party changelog commit and the official AWS supporting article. Documentation review only; no implementation was assessed."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://google.aip.dev/155",
          "title": "AIP-155: Request identification",
          "publisher": "Google",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T09:41:55Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "retry-contract-guidance",
          "url": "https://aws.amazon.com/builders-library/making-retries-safe-with-idempotent-APIs/",
          "title": "Making retries safe with idempotent APIs",
          "publisher": "Amazon Web Services",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T09:42:43Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "changelog-change",
          "url": "https://github.com/aip-dev/google.aip.dev/commit/71f6491a997370b572d003536a1f7ad0e8c1c511",
          "title": "AIP-155: correct the request message and add a changelog entry",
          "publisher": "Google AIP maintainers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T09:42:06Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "AIP-155 permits APIs to add request IDs and says they should be optional. The ID belongs to the request, not the resource. Its guarantees apply to the service's documented contract, not every API.",
        "The current-state response exception applies when reproducing the historical success response is infeasible. Idempotent effects do not require byte-identical response data.",
        "Caller scoping, changed-parameter rejection and coordinated identity/effect recording are AWS guidance, not explicit AIP-155 requirements. AWS describes service-dependent retention; it does not prescribe a universal lifetime.",
        "AIP-155's Created and Updated headers both display 2019-05-06. The corresponding first-party commit is timestamped 2024-01-26T17:45:54Z but adds a 2024-01-08 changelog entry. These are distinct maintenance signals, not new 2026 guidance.",
        "Authorization separation and completion limits are editorial synthesis. This resource establishes no incident, affected deployment, bounty, implementation correctness, current exposure or testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-aip-158-pagination-authorization-boundary",
      "title": "Google AIP-158: pagination continuation does not grant resource authority",
      "publisher": "Google",
      "authors": [],
      "primary_url": "https://google.aip.dev/158",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "Google's Approved pagination guidance separates a continuation position from permission to read the collection. Page tokens must be opaque and convey no authorization; each request still requires authorization. Subsequent requests retain the other query arguments, while page size may change. Opacity protects interface abstraction rather than establishing access rights.",
      "defensive_use": "Editorial lesson: document continuation state and actor/resource policy as separate design contracts. An integration following a stored cursor must still rely on the service's per-request authorization decision. Treat query continuity as a request-consistency requirement, not evidence of entitlement.",
      "prerequisites": [
        "Basic familiarity with paginated collection APIs and access-control modeling"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official API implementation guidance."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication of the current text is not established by the page's Created field."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No dated educational-resource edition is established for this living guidance."
        },
        "source_displayed": {
          "value": "2025-07-08",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Date of the newest displayed Changelog entry, concerning degraded-skip guidance; not original publication, an edition release, or the date of the authorization rule."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T04:05:09Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the official AIP page, shown as Approved, and the first-party commit corroborating its later changelog entry. This is a documentation review, not an implementation assessment."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://google.aip.dev/158",
          "title": "AIP-158: Pagination",
          "publisher": "Google",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T04:02:03Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "changelog-change",
          "url": "https://github.com/aip-dev/google.aip.dev/commit/1b7bc19ccd0fb19d8c24642eb2907d0246328c41",
          "title": "fix(AIP-158): clarify degraded skip response guidance (#1510)",
          "publisher": "Google AIP maintainers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T04:04:42Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "The page's Created and Updated fields both display 2019-02-18, although its changelog includes 2025-07-08. The linked first-party commit corroborates that later edit; the header is not treated as the current text's last revision date.",
        "Query-argument consistency excludes page size: the guidance requires honoring a changed page size and recommends rejecting changes to other arguments. This contract does not establish snapshot isolation or a fixed collection across pages.",
        "Opaque token format does not establish permission. This guide supplies no incident, affected-product, bounty, or deployment-specific security claim."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "google-aip-161-update-field-authority",
      "title": "Google API field masks: preserve server-owned and immutable state",
      "publisher": "Google",
      "authors": [],
      "primary_url": "https://google.aip.dev/161",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "authorization",
        "business-logic",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "untrusted-input-handling"
      ],
      "version": null,
      "summary": "Google's Approved field-mask guidance defines which resource fields participate in an update. Services must ignore output-only input whether selected directly or through a containing field. Supporting field-behavior guidance says unchanged immutable values should be ignored, while requested changes should return INVALID_ARGUMENT. Its annotations describe behavior but add no validation themselves.",
      "defensive_use": "Editorial synthesis: document caller authorization, the selected change set and server-enforced field mutability as separate contracts. Valid field selection does not establish permission to change it. Preserve each nested field's behavior independently of its parent, and keep business-state transitions outside generic updates when the API contract requires dedicated operations.",
      "prerequisites": [
        "Basic familiarity with resource-oriented APIs, partial updates and access-control modeling"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official Google API design and implementation guidance."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The pages' Created fields do not establish original publication of their current text."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No dated educational-resource edition is established for this living guidance."
        },
        "source_displayed": {
          "value": "2023-10-18",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Newest displayed AIP-161 Changelog entry, concerning output-only fields in update masks. It is not original publication, an edition release or the current text's last revision date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T08:05:38Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed AIP-161 and supporting AIP-203/AIP-134, each shown as Approved, plus first-party commits distinguishing displayed changelog dates from later source maintenance. Documentation review only; no implementation was assessed."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://google.aip.dev/161",
          "title": "AIP-161: Field masks",
          "publisher": "Google",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T08:02:47Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "field-behavior",
          "url": "https://google.aip.dev/203",
          "title": "AIP-203: Field behavior documentation",
          "publisher": "Google",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T08:02:58Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "standard-update",
          "url": "https://google.aip.dev/134",
          "title": "AIP-134: Standard methods: Update",
          "publisher": "Google",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T08:02:58Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "output-only-change",
          "url": "https://github.com/aip-dev/google.aip.dev/commit/9d73091cb8519085c695a0d1388f7e35ea9e0686",
          "title": "AIP-161/AIP-203: converge output-only update-mask guidance",
          "publisher": "Google AIP maintainers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T08:04:34Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "field-mask-link-maintenance",
          "url": "https://github.com/aip-dev/google.aip.dev/commit/ea79190087e673482c2579e6f38c9dbe5a287db2",
          "title": "AIP-161: link to AIP-157",
          "publisher": "Google AIP maintainers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T08:04:34Z",
          "supports": [
            "dates"
          ]
        },
        {
          "id": "field-behavior-maintenance",
          "url": "https://github.com/aip-dev/google.aip.dev/commit/1f058efe4558aabe605daaff13b0d18d4563707d",
          "title": "AIP-203: clarify optional field presence and field behavior",
          "publisher": "Google AIP maintainers",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T08:05:28Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "AIP-161's Created and Updated headers both show 2021-03-01. Its displayed output-only changelog date is 2023-10-18, while the corresponding first-party commit is timestamped 2023-10-19T15:57:39Z. A later 2025-03-28 commit added an AIP-157 link; neither header nor newest displayed changelog establishes the last source revision.",
        "AIP-203's headers show 2018-07-17 and its newest displayed changelog entry is 2023-09-14, although a reviewed 2026-06-25 commit adds an optional-field clarification. AIP-134's headers show 2019-01-24 while its newest displayed changelog entry is 2025-10-03. These dates are not interchangeable publication or edition dates.",
        "AIP-203 forbids an error merely because output-only input is present and requires it to be cleared or ignored. This differs from immutable input, for which unchanged values should be ignored and changes should cause a validation error. Nested field behavior is independent of its parent's annotation.",
        "AIP-134 says generic updates should avoid side effects and state fields must not be directly writable through them. The separation of field selection from caller authorization is editorial synthesis; these AIPs' explicit rules concern field behavior and update semantics.",
        "These are Google API design requirements, not universal protocol guarantees or proof that a particular service enforces them. This resource establishes no incident, affected deployment, bounty, exploitability or testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "graphql-ruby-2026-authorization-exception-integrity",
      "title": "GraphQL-Ruby: authorization exceptions must stop execution",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Bas Alberts"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2026-152_graphql-ruby/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "error-response-design",
        "patch-verification"
      ],
      "version": "GHSL-2026-152 / GHSA-j7xr-4g94-r9h3",
      "summary": "A GraphQL-Ruby execution-engine path converted a resolver authorization exception into permission to continue. Research demonstrates a denied resolver running and returning a fixture value, while the legacy engine stopped it. This illustrates why error handling must preserve the security meaning of a denial.",
      "defensive_use": "The maintainer identifies versions 2.5.23 through 2.6.5 as affected and 2.6.6 as patched. Only the newer Execution::Next mode and resolver-thrown authorization errors are implicated; other authorization forms worked correctly. Editorial lesson: preserve denial semantics across execution engines and keep error formatting separate from authority to execute.",
      "prerequisites": [
        "Basic API access-control concepts",
        "Familiarity with server-side data processing"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-08-08",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "A separate resource-version release is not established. Software patch-release chronology is preserved in the caveats."
        },
        "source_displayed": {
          "value": "2026-08-08",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:28:33Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary research and maintainer evidence reviewed. Article immutability and deployment remediation were not established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2026-152_graphql-ruby/",
          "title": "GHSL-2026-152: Privilege escalation via authorization bypass in graphql-ruby",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-advisory",
          "url": "https://github.com/rmosolgo/graphql-ruby/security/advisories/GHSA-j7xr-4g94-r9h3",
          "title": "Authorization Bypass in Execution::Next",
          "publisher": "GraphQL-Ruby",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:10:00Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "maintainer-changelog",
          "url": "https://raw.githubusercontent.com/rmosolgo/graphql-ruby/v2.6.6/CHANGELOG.md",
          "title": "GraphQL-Ruby 2.6.6 changelog",
          "publisher": "GraphQL-Ruby",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:28:33Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The research reports testing 2.6.5 and reproducing the behavior on 2.6.1. Its fixture demonstrates resolver execution and returned data; database deletion, external calls and broader privilege escalation are possible application-dependent consequences, not demonstrated production incidents.",
        "The application must use the affected execution mode and deny access by raising the relevant authorization exception. This is not a claim that all GraphQL-Ruby deployments bypassed authorization.",
        "Research timeline: reported July 16, acknowledged and fixed July 17, 2026. Maintainer advisory and patched release date are July 21; detailed research publication is August 8.",
        "No CVE is identified in the maintainer advisory. Discovery is credited to GitHub Security Lab Taskflow Agent with manual verification; Bas Alberts is the research byline. No patch reproduction was performed."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "grav-2026-session-account-state-revalidation",
      "title": "Grav API: account-disable enforcement across session authenticators",
      "publisher": "Grav",
      "authors": [
        "rhukster"
      ],
      "primary_url": "https://github.com/getgrav/grav/security/advisories/GHSA-7qfj-82q8-frw6",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "GHSA-7qfj-82q8-frw6 describes inconsistent account-disable enforcement across authentication methods. Existing browser or remembered sessions could retain API authority because refreshed permissions did not also establish current account validity.",
      "defensive_use": "Editorial lesson: authentication state is a revocable claim. Every authentication method should enforce the same account-lifecycle invariants, and failed account refresh must remove authority rather than preserve cached permission. The advisory describes requiring a freshly loaded, enabled account and failing closed on refresh errors. The official 1.0.36 release notes state that disabling or deleting an account immediately terminates its API sessions; this is maintainer-stated remediation, not an independently tested result.",
      "prerequisites": [
        "Basic understanding of authentication, account state and authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-09-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition date established; software fix versions are discussed separately."
        },
        "source_displayed": {
          "value": "2026-09-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T03:23:22Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory, official 1.0.36 release notes and GitHub release metadata reviewed; release availability and maintainer-stated remediation are established, but no deployment assessment or independent patch test was performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/getgrav/grav/security/advisories/GHSA-7qfj-82q8-frw6",
          "title": "Disabled grav-plugin-api accounts retain access through existing sessions",
          "publisher": "Grav",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T03:21:15Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release-1-0-36",
          "url": "https://github.com/getgrav/grav-plugin-api/releases/tag/1.0.36",
          "title": "Grav API 1.0.36 release notes",
          "publisher": "Grav",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T03:23:08Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "release-1-0-36-metadata",
          "url": "https://api.github.com/repos/getgrav/grav-plugin-api/releases/tags/1.0.36",
          "title": "Official GitHub release metadata for Grav API 1.0.36",
          "publisher": "Grav / GitHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T03:21:15Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires an already authorized session belonging to the subsequently disabled account. The maintainer describes static-review findings, not a demonstrated production compromise. Retained access is bounded by prior permissions and session lifetime; no additional privilege is claimed.",
        "The advisory lists affected versions through 1.0.35 and names 1.0.36 as patched, but its body still says no patch is available. That stale internal discrepancy remains in the advisory. The separately reviewed official 1.0.36 release and notes establish release availability and maintainer-stated session-revocation remediation, not independent verification of patch effectiveness.",
        "Official GitHub release metadata records 1.0.36 as published on 2026-09-19 at 00:06:19 UTC, before the advisory's 2026-09-23 publication. This is the software release chronology, not the educational resource's edition date, the original report date or a verified deployment-fix date; dates.version_released remains null.",
        "rhukster published the advisory and credits AlpetGexha as reporter; the 1.0.36 release notes also credit AlpetGexha for the account-session remediation. Original report date is unknown. Learning prerequisites and the invariant formulation are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "hackerone-quality-vulnerability-reports",
      "title": "Quality Reports",
      "publisher": "HackerOne Help Center",
      "authors": [],
      "primary_url": "https://docs.hackerone.com/en/articles/8475116-quality-reports",
      "resource_type_id": "reporting-guide",
      "topic_ids": [
        "reporting"
      ],
      "skillset_ids": [
        "defensive-evidence-writing"
      ],
      "version": null,
      "summary": "Official guidance for concise security reports: clear titles, expected versus actual behavior, evidence-backed impact, useful supporting material, scope checks, and remediation suggestions.",
      "defensive_use": "Document a finding from authorized work with clear impact, evidence limits, and remediation context; omit unrelated details.",
      "prerequisites": [
        "Understanding of the program’s authorized scope",
        "A documented finding from authorized work"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2025-02-05",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Date displayed by the help article; original publication versus update is not distinguished."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T14:58:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Review records accessible official guidance as of this date; living content and current versions may change."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://docs.hackerone.com/en/articles/8475116-quality-reports",
          "title": "Quality Reports",
          "publisher": "HackerOne Help Center",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T14:58:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The official source includes technical examples; this catalog retains reporting-quality lessons only."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "hotcrp-2026-contact-authorship-permission-boundary",
      "title": "HotCRP: separate submission visibility from authorship authority",
      "publisher": "HotCRP",
      "authors": [
        "kohler"
      ],
      "primary_url": "https://github.com/kohler/hotcrp/security/advisories/GHSA-v8jx-vq6p-jq52",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "GHSA-v8jx-vq6p-jq52 describes an API permission gap between viewing a submission and changing contact authorship. The maintainer reports that reviewers and program-committee members could obtain author-level access to submissions they could already view, affecting anonymity and integrity.",
      "defensive_use": "Editorial lesson: authority-changing metadata needs its own permission check; visibility alone must not authorize membership changes. The advisory identifies versions 3.0.0–3.3.1 as affected and 3.4 as fixed. Release notes date 3.4 to August 5, before disclosure on August 11.",
      "prerequisites": [
        "Basic server-side identity and authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-08-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established. Software patch-release date 2026-08-05 is distinct from resource publication."
        },
        "source_displayed": {
          "value": "2026-08-11",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T10:29:18Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory and release notes reviewed. Deployment state and source immutability are not established."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/kohler/hotcrp/security/advisories/GHSA-v8jx-vq6p-jq52",
          "title": "Escalation to author access by reviewers",
          "publisher": "HotCRP",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:29:18Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release-notes",
          "url": "https://github.com/kohler/hotcrp/blob/master/NEWS.md",
          "title": "HotCRP release notes: version 3.4",
          "publisher": "HotCRP",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:29:18Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires an authenticated reviewer or program-committee member and existing submission visibility; this is not an unauthenticated access claim.",
        "The maintainer reports an action-log review finding no exploitation on its hosted service. That statement does not establish absence of incidents in other deployments. The advisory reports capability and consequences, without a separate production-incident narrative.",
        "kohler published the advisory; discovery is credited to an internal audit without a named individual reporter. The original report date is unknown.",
        "This review did not independently verify the patch implementation or deployed state. Upgrade evidence does not establish reversal of any prior unauthorized authorship changes. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "langflow-2026-mcp-resource-project-authorization",
      "title": "Langflow: project transport authorization must reach each resource read",
      "publisher": "Langflow",
      "authors": [],
      "primary_url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-4hmc-cfm3-w43c",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "ai-security",
        "authorization",
        "identity"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "ai-authority-boundaries",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-09-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication; not software release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned educational edition established."
        },
        "source_displayed": {
          "value": "2026-09-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication; not software release."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:39:19Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory reviewed; no vulnerability execution or deployment testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-4hmc-cfm3-w43c",
          "title": "Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers",
          "publisher": "Langflow",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:39:19Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "content_scope": "defensive_education",
      "summary": "The maintainer confirms that project-level MCP authentication did not authorize later file reads. Resource handlers reached storage without retaining user and project restrictions. A local two-user demonstration showed cross-user file disclosure, contrasting with denial by the ordinary download interface.",
      "defensive_use": "The documented fix carries authenticated context into object resolution, constrains project membership, and scopes discovery results. Editorial lesson: connection admission and storage containment cannot replace per-resource authorization; compare policy across every interface to the same object.",
      "prerequisites": [
        "Object ownership and project membership models",
        "MCP resource handling and application storage separation"
      ],
      "caveats": [
        "Source prerequisites include authentication-enabled deployments, an accessible owned project, and another user’s uploaded flow-backed file.",
        "The maintainer corrects affected versions to 1.6.8–1.9.0 and identifies 1.9.1, released April 24, 2026, as fixed. September publication is not patch timing.",
        "The September 22 triage update reports regression coverage; this review did not independently run it. No observed production compromise or award is established.",
        "Conceptual defensive summary; public disclosure grants no testing authorization.",
        "The advisory credits R1ZZG0D as Reporter, andifilhohub as Analyst, and erichare as Remediation developer. Its header identifies andifilhohub as the publishing account. No explicit author byline is shown, so named authors remain unestablished rather than inferred from those roles."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "librechat-2026-agent-context-mutation-authority",
      "title": "LibreChat: agent edit authority must cover attached context",
      "publisher": "LibreChat",
      "authors": [],
      "primary_url": "https://github.com/LibreChat-AI/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "ai-security",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "ai-authority-boundaries",
        "patch-verification"
      ],
      "version": null,
      "summary": "The advisory contrasts denied access to a private agent with accepted changes to its attached files. Upload handling omitted the agent permissions enforced elsewhere, allowing unauthorized context and search-file additions. The documented demonstration changed the owner-visible agent response. This is an application authorization failure before model interpretation.",
      "defensive_use": "The source recommends checking agent-edit permission for uploads. Editorial review principle: enumerate every mutation of an agent’s effective context, including attachments and retrieval indexes; hiding its configuration does not protect those mutations.",
      "prerequisites": [
        "Object-level authorization and agent context composition"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-01-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-01-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned educational edition established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T16:19:05Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory reviewed; no vulnerability execution or deployment testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/LibreChat-AI/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59",
          "title": "LibreChat Insufficient Access Control on Agent Files",
          "publisher": "LibreChat",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T16:19:05Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The advisory credits Lisa Gnedt and Michael Koppmann of SBA Research, with GitHub Reporter credits for lxp and mkoppmann. It does not display an explicit author byline; these credits alone do not establish advisory authorship, so named authors remain unestablished.",
        "Requires an authenticated account and knowledge of another agent’s identifier; private agents were not ordinarily visible.",
        "CVE-2025-69220: the advisory identifies 0.8.1-rc2 as affected and records the 0.8.2-rc2 fix release on January 7, 2026.",
        "No production compromise, data theft, or award is established. Broader model behavior depends on application context; this review did not run the demonstration."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "librechat-2026-mcp-oauth-session-binding",
      "title": "LibreChat: delegated credentials must remain bound to the initiating session",
      "publisher": "LibreChat",
      "authors": [
        "danny-avila"
      ],
      "primary_url": "https://github.com/LibreChat-AI/LibreChat/security/advisories/GHSA-vf7j-7mrx-hp7g",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "ai-security",
        "authorization",
        "identity"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "ai-authority-boundaries",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-03-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication; not software release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned educational edition established."
        },
        "source_displayed": {
          "value": "2026-03-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication; not software release."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:39:19Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory reviewed; no vulnerability execution or deployment testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/LibreChat-AI/LibreChat/security/advisories/GHSA-vf7j-7mrx-hp7g",
          "title": "MCP OAuth callback does not validate browser session, allows token theft via redirect link",
          "publisher": "LibreChat",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:39:19Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "content_scope": "defensive_education",
      "summary": "CVE-2026-31944 describes an MCP OAuth callback that trusted cached initiator identity without authenticating the returning browser or checking identity continuity. The advisory describes third-party credentials being associated with the wrong local account. Consequences are bounded by delegated integration scopes, not takeover of the affected person’s LibreChat account.",
      "defensive_use": "Editorial lesson: bind OAuth initiation, callback session, and credential-storage owner before accepting a grant. Treat transaction state as correlation, not sufficient proof of browser identity. The advisory names 0.8.3-rc1 as patched but does not explain its implementation.",
      "prerequisites": [
        "OAuth authorization-code callbacks and transaction state",
        "Local session identity versus external delegated authority"
      ],
      "caveats": [
        "Prerequisites include an authenticated initiator, enabled MCP OAuth, and another person’s interaction with the authorization flow; existing provider consent can change the interaction required.",
        "The source lists affected versions as >= v0.8.2, <= 0.8.2-rc3. Preserve this unusual stable/prerelease range without silently normalizing it.",
        "No independent production-compromise evidence, patch-release date, historical-token revocation behavior, or award amount is established.",
        "Conceptual defensive summary; public disclosure grants no testing authorization."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "librechat-2026-mcp-view-secret-projection",
      "title": "LibreChat: viewing an integration must not reveal its service secrets",
      "publisher": "LibreChat",
      "authors": [
        "LoGGGG2402"
      ],
      "primary_url": "https://github.com/LibreChat-AI/LibreChat/security/advisories/GHSA-6vqg-rgpm-qvf9",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "ai-security",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "secrets-containment",
        "ai-authority-boundaries",
        "secure-parser-review"
      ],
      "version": null,
      "summary": "The MCP registry prepared decrypted configuration for internal use, and response handlers returned that representation to viewers without removing secrets. Object visibility consequently became credential disclosure authority. The advisory documents a local demonstration exposing administrator-managed provider credentials to a view-only account.",
      "defensive_use": "The source recommends secret-free responses and presence indicators. Editorial review principle: define separate execution and presentation representations, then verify that list and detail responses preserve the same field-level disclosure policy.",
      "prerequisites": [
        "Integration credentials, response serialization, and object versus field authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-06-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-06-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned educational edition established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T16:19:05Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory reviewed; no vulnerability execution or deployment testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/LibreChat-AI/LibreChat/security/advisories/GHSA-6vqg-rgpm-qvf9",
          "title": "Shared MCP Server View Leaks Decrypted Admin Secrets",
          "publisher": "LibreChat",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T16:19:05Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires MCP enabled, stored administrator-managed secrets, and viewer access to the shared integration.",
        "CVE-2026-44653: affected v0.8.3 and patched v0.8.4 are listed; patch release date is not established by the advisory. March 13 is the reported test date, not publication.",
        "Credential reuse and indirect exposure through shared agents are possible extensions discussed by the source, not demonstrated outcomes. No production compromise or award is established."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "lobehub-2026-knowledge-membership-mutation-authority",
      "title": "LobeHub: knowledge-base membership changes require ownership authorization",
      "publisher": "LobeHub",
      "authors": [],
      "primary_url": "https://github.com/lobehub/lobehub/security/advisories/GHSA-j7xp-4mg9-x28r",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "ai-security",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "ai-authority-boundaries",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary-source disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-01-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Displayed publication date of the primary educational source; not software patch timing."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned educational edition established."
        },
        "source_displayed": {
          "value": "2026-01-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Displayed publication date of the primary educational source; not software patch timing."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:59:14Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Public primary sources reviewed; no software execution or deployment testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/lobehub/lobehub/security/advisories/GHSA-j7xp-4mg9-x28r",
          "title": "IDOR in Knowledge Base File Removal Allows Cross User File Deletion",
          "publisher": "LobeHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:59:14Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "content_scope": "defensive_education",
      "summary": "The maintainer advisory attributes cross-user knowledge-base file removal to an omitted ownership restriction in a database mutation. Its reported demonstration shows one deletion result. The boundary is between being authenticated and being authorized to change another user’s retrieval corpus.",
      "defensive_use": "Editorial review principle: enforce ownership at the mutation, including every relationship being removed. Random identifiers reduce accidental discovery but do not prove permission. Review negative cross-owner cases and verify which underlying objects a removal actually changes.",
      "prerequisites": [
        "Object ownership and relationship-level authorization",
        "Retrieval-augmented generation knowledge-base lifecycle"
      ],
      "caveats": [
        "The advisory credits DenizParlak as Reporter but does not display an explicit author byline. Reporter credit alone does not establish advisory authorship, so named authors remain unestablished.",
        "CVE-2026-23522 requires authentication and knowledge of both relevant identifiers according to the narrative; its displayed severity vector instead says no privileges. Preserve that discrepancy.",
        "The source lists versions through v2.0.0-next.192 as affected and v2.0.0-next.193 as patched; it supplies no patch date or implementation detail.",
        "Reported removal could disrupt retrieval. Permanent erasure of underlying stored documents, production compromise and an award are not independently established.",
        "Conceptual defensive summary only; public disclosure grants no testing authorization."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "mailcow-2026-persisted-data-query-boundary",
      "title": "mailcow: stored configuration retains its original trust level",
      "publisher": "mailcow",
      "authors": [
        "FreddleSpl0it"
      ],
      "primary_url": "https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-r8fq-wrfm-cj2q",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and official release documentation."
      },
      "dates": {
        "published": {
          "value": "2026-04-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication, separate from software remediation chronology."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established; software patch releases are described in defensive_use."
        },
        "source_displayed": {
          "value": "2026-04-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit primary advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T09:09:13Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and release documentation reviewed. No reproduction, live-target access, or independent patch testing."
      },
      "content_scope": "defensive_education",
      "summary": "The maintainer advisory for CVE-2026-40871 describes stored configuration being reused unsafely in later database-query construction. Persistence did not make the originally supplied value trustworthy. The source reports disclosure of an administrator password hash through downstream notification processing. High-privilege API access and execution of the affected background processing are prerequisites; unauthenticated access is not established.",
      "defensive_use": "The advisory identifies 2026-03b as the repair boundary; the official blog dates that software release to March 31, 2026 and describes input-validation and escaping improvements. Editorial lesson: preserve data-only semantics at every consumer, parameterize database values, validate structured configuration, and apply least privilege to background database access.",
      "prerequisites": [
        "Stored-data trust provenance and asynchronous background processing",
        "Parameterized database queries and service-account least privilege"
      ],
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-r8fq-wrfm-cj2q",
          "title": "Second Order SQL Injection in quarantine category via API",
          "publisher": "mailcow",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:09:13Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release-blog",
          "url": "https://mailcow.email/posts/2026/release-2026-03/",
          "title": "March 2026 release announcement, revision B",
          "publisher": "The Infrastructure Company GmbH",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:09:13Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/mailcow/mailcow-dockerized/releases/tag/2026-03b",
          "title": "mailcow 2026-03b release",
          "publisher": "mailcow",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:09:13Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "lukehebe is the credited reporter; FreddleSpl0it published the advisory. No bounty amount is established.",
        "The source asserts broader compromise possibilities; those are not established by the reported hash-disclosure demonstration. No independent reproduction was performed.",
        "Release notes broadly describe validation and escaping changes. This review does not establish every patch implementation detail or claim parameterization was the exact shipped repair.",
        "The software release predates advisory publication. The blog update date is not the patch date. Learning prerequisites and generalized design guidance are editorial."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "mcp-elicitation-consent-credential-custody",
      "title": "MCP elicitation: consent, credential custody and completion",
      "publisher": "Model Context Protocol",
      "authors": [],
      "primary_url": "https://modelcontextprotocol.io/specification/2026-07-28/client/elicitation",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "ai-security",
        "authorization",
        "identity"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "integration-threat-modeling",
        "secrets-containment"
      ],
      "version": "2026-07-28 specification URL",
      "summary": "Form elicitation excludes secrets. URL elicitation places sensitive interactions outside the MCP client and model context, with the requesting server and destination visible to the user. Agreeing to open the interaction is not completion evidence; the server determines completion separately. For third-party OAuth, the MCP server holds the resulting credentials; this grant is separate from the client's authorization to access that server.",
      "defensive_use": "Editorial guidance: map the data recipient, credential holder and authoritative completion evidence for each interaction. Preserve decline and cancellation, bind completion to the initiating identity, and review navigation consent and automatic URL handling independently.",
      "prerequisites": [
        "MCP client/server roles, OAuth delegation and credential storage"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official specification."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication date not established."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "A versioned URL alone does not establish an edition release date."
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate page date established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T15:34:19Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed elicitation and the specification overview. No implementation-conformance assessment."
      },
      "sources": [
        {
          "id": "elicitation",
          "url": "https://modelcontextprotocol.io/specification/2026-07-28/client/elicitation",
          "title": "Elicitation",
          "publisher": "Model Context Protocol",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T15:33:23Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "overview",
          "url": "https://modelcontextprotocol.io/specification/2026-07-28",
          "title": "Specification: Security and Trust & Safety",
          "publisher": "Model Context Protocol",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T15:33:23Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "The form prohibition concerns access or transaction secrets; ordinary contact data is not categorically excluded.",
        "Elicitation prohibits automatic URL or metadata prefetching and navigation without explicit consent. It requires the full URL to be shown and credentials to stay out of URLs.",
        "The overview states that protocol rules alone cannot enforce its security principles; implementation controls remain necessary.",
        "No deployed vulnerability, remediation or award is established. The URL version is preserved separately from unknown publication and release dates."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "mcp-progressive-scope-authority",
      "title": "MCP scope selection: progressive consent and accumulated authority",
      "publisher": "Model Context Protocol",
      "authors": [],
      "primary_url": "https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "ai-security",
        "authorization",
        "identity"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "ai-authority-boundaries"
      ],
      "version": "2026-07-28 documentation URL",
      "summary": "Server permission challenges shape what a general-purpose MCP client requests. Broad discovery metadata and accumulated scopes can enlarge delegated authority. Token scopes still require application-side authorization.",
      "defensive_use": "Map operations to permissions, issue focused challenges, support reduced grants and record elevations. Review initial discovery and subsequent consent together; do not assume every authorization request represents only the current operation.",
      "prerequisites": [
        "OAuth scope and consent concepts; client/server authorization responsibilities"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official documentation."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The versioned URL does not establish a publication or release date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The versioned URL does not establish a publication or release date."
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The versioned URL does not establish a publication or release date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T16:49:11Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed scope-minimization guidance; no deployment assessment."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices",
          "title": "Security Best Practices: Scope Minimization",
          "publisher": "Model Context Protocol",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T16:49:11Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "The guide permits several challenge-breadth strategies. When an initial challenge omits scope, it documents requesting all advertised scopes; it does not universally require the narrowest request.",
        "Maintained guidance, not evidence of a specific deployment’s exposure or a verified patch. Publication and edition dates remain unknown; the URL version is preserved separately."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "microsoft-compensating-transaction-state-integrity",
      "title": "Microsoft compensating transactions: recovery must preserve valid concurrent state",
      "publisher": "Microsoft Azure Architecture Center",
      "authors": [],
      "primary_url": "https://learn.microsoft.com/en-us/azure/architecture/patterns/compensating-transaction",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "Explains recovery after partial completion across services or data stores. Compensation applies domain-specific corrective effects; restoring an earlier snapshot can overwrite valid concurrent changes. Recovery can itself fail, and some committed effects cannot be meaningfully reversed.",
      "defensive_use": "Editorial lesson: distinguish an atomic transaction boundary from a process spanning independently committed operations. Model completion evidence, compensable effects and irreversible commitments. Preserve recovery progress and repeat-safe corrective actions while respecting concurrent work and business entitlements.",
      "prerequisites": [
        "Basic distributed operations, eventual consistency and application state invariants"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "The official architecture article and its public source were readable without sign-in."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication was not established."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No dated resource edition is identified."
        },
        "source_displayed": {
          "value": "2026-04-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Rendered page’s Last updated date; not original publication or latest repository modification."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T05:52:30Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Official page, pinned first-party source and two later file changes reviewed. Maintained living guidance without a numbered edition."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://learn.microsoft.com/en-us/azure/architecture/patterns/compensating-transaction",
          "title": "Compensating Transaction pattern",
          "publisher": "Microsoft",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T05:50:04Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "source-metadata",
          "url": "https://github.com/MicrosoftDocs/architecture-center/blob/498e83a207cfd512b396489e95ed3f791b372364/docs/patterns/compensating-transaction.md",
          "title": "Compensating Transaction pattern source at reviewed revision",
          "publisher": "MicrosoftDocs",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T05:52:09Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "august-link-maintenance",
          "url": "https://github.com/MicrosoftDocs/architecture-center/commit/d73cd1632ffa489eff78a16bba4d101c510a1810",
          "title": "August 2026 idempotent-command link maintenance",
          "publisher": "MicrosoftDocs",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T05:51:29Z",
          "supports": [
            "dates"
          ]
        },
        {
          "id": "september-link-maintenance",
          "url": "https://github.com/MicrosoftDocs/architecture-center/commit/498e83a207cfd512b396489e95ed3f791b372364",
          "title": "September 2026 related-document link maintenance",
          "publisher": "MicrosoftDocs",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T05:51:29Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "Compensation does not guarantee restoration of the original state. It is unsuitable where temporary inconsistency is unacceptable or valid recovery cannot be assured.",
        "Recovery remains domain-specific and may require human intervention. Repeat-safe recovery steps do not make irreversible commitments undoable or guarantee eventual completion.",
        "The rendered page displays 2026-04-20; the pinned source metadata says 2026-04-16. The reviewed August 14 and September 28, 2026 changes only update links in this file. These are distinct maintenance signals, not publication or edition-release dates.",
        "Architecture guidance, not an incident, vulnerability disclosure, implementation audit, bounty claim or testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "microsoft-copilot-2026-streaming-output-activation-boundary",
      "title": "SearchLeak: streamed output needs policy enforcement before browser activation",
      "publisher": "Varonis Threat Labs",
      "authors": [
        "Dolev Taler"
      ],
      "primary_url": "https://www.varonis.com/blog/searchleak",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "ai-security",
        "web-foundations",
        "interpreter-boundaries"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "untrusted-input-handling",
        "concurrency-reasoning"
      ],
      "version": null,
      "summary": "SearchLeak (CVE-2026-42824) illustrates a timing gap between streamed AI output becoming active in a browser and final-response sanitization. Varonis reports email-subject disclosure in a larger chain containing this failure. Cleaning the completed response cannot reverse effects that already occurred.",
      "defensive_use": "Define output-safety invariants for every observable intermediate state, not just the completed answer. Keep generated content inert until applicable policy checks have passed. Review rendering and data-disclosure boundaries together; a clean final display is insufficient evidence that no earlier side effect occurred.",
      "prerequisites": [
        "Browser rendering, sanitization and content-security-policy concepts",
        "AI output trust boundaries and ordering of security checks"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public researcher article and Microsoft-authored CNA record."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The catalog lists June 15, 2026, but does not distinguish original publication from later updating."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition is established."
        },
        "source_displayed": {
          "value": "2026-06-15",
          "precision": "day",
          "basis": "explicit",
          "source_id": "researcher",
          "note": "The article labels this date as last updated."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T19:43:06Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Researcher article, publisher catalog and Microsoft CNA record read. Microsoft's direct advisory returned a JavaScript shell; vendor corroboration here comes from the CNA record. No behavior was independently reproduced."
      },
      "sources": [
        {
          "id": "researcher",
          "url": "https://www.varonis.com/blog/searchleak",
          "title": "SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon",
          "publisher": "Varonis Threat Labs",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T19:41:28Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "publisher-catalog",
          "url": "https://www.varonis.com/blog/all",
          "title": "Varonis Blog catalog: SearchLeak entry",
          "publisher": "Varonis",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T19:41:39Z",
          "supports": [
            "dates"
          ]
        },
        {
          "id": "microsoft-cna",
          "url": "https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42824.json",
          "title": "Microsoft CNA record for CVE-2026-42824",
          "publisher": "Microsoft via CVE Program",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T19:42:30Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The reported conditions require affected enterprise search, relevant content accessible to the victim and the victim opening a supplied link. This resource isolates the timing boundary; disclosure also depended on additional weaknesses.",
        "Wider indexed-content exposure depends on the victim's access. Account takeover is a proposed consequence, not a demonstrated result in this record.",
        "Varonis says Microsoft patched the issue. The exact fix date and implementation are not established by the reviewed evidence.",
        "The Microsoft CNA record corroborates network information disclosure requiring user interaction and identifies an exclusively hosted service. It supplies no usable affected-version range. Its CWE-77 classification does not establish operating-system command execution.",
        "The CNA's June 4, 2026 public-disclosure date and September 24 update date describe the vulnerability record, not this article's publication or remediation chronology.",
        "No individual award amount or affected-victim count is established. This educational record grants no testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "microsoft-graph-batch-member-authorization-outcomes",
      "title": "Microsoft Graph batching: preserve each member authorization outcome",
      "publisher": "Microsoft",
      "authors": [
        "FaithOmbongi"
      ],
      "primary_url": "https://learn.microsoft.com/en-us/graph/json-batching",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "error-response-design"
      ],
      "version": null,
      "summary": "Microsoft Graph documentation distinguishes batch-envelope success from individual outcomes. Its example includes permission denials inside a successful batch response. Member results can arrive in a different order and must be correlated by their identifiers. Dependency failures and per-member throttling are separate outcomes, not evidence of an authorization decision.",
      "defensive_use": "Editorial synthesis: keep transport completion, permission for each operation and application-level completion separate. Preserve a member's denied, failed or unresolved state when presenting an overall result or composing downstream state. Define what partial completion means for the application rather than turning a successful envelope into blanket success. A correlation identifier associates evidence; it grants no authority. Dependency ordering alone should not be treated as an atomic rollback guarantee.",
      "prerequisites": [
        "Basic familiarity with API authorization, response handling and application state transitions"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official documentation and first-party source metadata were readable at review."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The displayed last-updated date does not establish original publication."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately dated educational-resource edition is established."
        },
        "source_displayed": {
          "value": "2025-02-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Microsoft Learn last-updated date, also present in source metadata; distinct from source-control chronology."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T11:04:40Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the documentation, pinned first-party source and file history. This was a documentation review; no service or application was tested."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://learn.microsoft.com/en-us/graph/json-batching",
          "title": "Combine multiple HTTP requests using JSON batching",
          "publisher": "Microsoft Learn",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T11:02:25Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "source-metadata",
          "url": "https://github.com/microsoftgraph/microsoft-graph-docs-contrib/blob/eabb8ccf73be8b116259cf219e05c98f31dd4b30/concepts/json-batching.md",
          "title": "JSON batching documentation source and metadata",
          "publisher": "Microsoft Graph documentation contributors",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T11:04:31Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "source-history",
          "url": "https://api.github.com/repos/microsoftgraph/microsoft-graph-docs-contrib/commits?path=concepts/json-batching.md&per_page=3",
          "title": "First-party JSON batching file history",
          "publisher": "Microsoft Graph documentation contributors",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T11:03:30Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "Source metadata explicitly identifies FaithOmbongi as author. This records that metadata, not sole authorship of all revisions.",
        "The most recent file-history entry reviewed is commit eabb8ccf73be8b116259cf219e05c98f31dd4b30, dated 2025-02-25. It is distinct from the displayed 2025-02-21 update date and is not an edition-release or new-2026 publication claim.",
        "The page links a separate known-issues listing that was not reviewed; this record does not claim complete coverage of current batching limitations.",
        "The reviewed page supplies no atomic rollback guarantee. The application-completion and authority distinctions above are editorial guidance, not a claim about every batch API or an undocumented Microsoft Graph vulnerability.",
        "No request examples, payloads, operational sequences or retry recipes are reproduced. This resource establishes no incident, affected deployment, bounty, current exposure or testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "mlflow-2026-alternate-interface-authorization-consistency",
      "title": "MLflow: authorization must survive alternate resource interfaces",
      "publisher": "Tachyon",
      "authors": [
        "Aakash Japi"
      ],
      "primary_url": "https://tachyon.so/blog/cve-2025-14297-mlflow-authorization-bypass",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary sources readable without an account."
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:19:04Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed primary disclosure and maintainer corroboration; no independent vulnerability reproduction performed."
      },
      "content_scope": "defensive_education",
      "summary": "Tachyon’s 2026 account of CVE-2025-14297 describes resource permissions depending on incomplete interface registration. Authentication could succeed while a missing authorization mapping permitted resource access. The researcher demonstrates restricted artifact reads and describes unauthorized writes and metadata access; the maintainer’s artifact-interface change corroborates a concrete enforcement gap.",
      "defensive_use": "Document one actor/action/resource policy shared by all interfaces. Treat new helper interfaces as additions to the authorization model, and make missing enforcement fail closed. Compare remediation claims with the actual maintainer change: the reviewed artifact patch aligns alternate interface recognition with permission enforcement.",
      "prerequisites": [
        "Authentication versus object-level authorization",
        "Applications with multiple interfaces to shared resources"
      ],
      "dates": {
        "published": {
          "value": "2026-02-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": "Publication of the detailed researcher article, not initial vulnerability reporting or first public disclosure."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Artifact enforcement patch merged January 19, 2026; the first containing release was not established."
        },
        "source_displayed": {
          "value": "2026-02-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": "Article publication date."
        }
      },
      "sources": [
        {
          "id": "research",
          "url": "https://tachyon.so/blog/cve-2025-14297-mlflow-authorization-bypass",
          "title": "CVE-2025-14297: MLflow Authorization Bypass",
          "publisher": "Tachyon",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:19:04Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "artifact-fix",
          "url": "https://github.com/mlflow/mlflow/pull/20035",
          "title": "Enforce authorization on AJAX proxy artifact APIs",
          "publisher": "MLflow",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:19:04Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "graphql-change",
          "url": "https://github.com/mlflow/mlflow/commit/87dc3fcab10bb79980b33d5485bb60fc1ef76f6d",
          "title": "Add an env var for controlling whether to enable GraphQL routes authorization",
          "publisher": "MLflow",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:19:04Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "The researcher limits exposure to self-hosted OSS basic-auth deployments with authenticated non-admin users; Databricks-managed MLflow is excluded.",
        "Downstream code execution is a conditional modeled consequence in the article, not demonstrated production compromise or an automatic result of data access.",
        "The article links a GraphQL commit that adds an authorization configuration switch; that commit alone does not establish the original GraphQL enforcement implementation or its complete patch chronology.",
        "The maintainer artifact patch merged January 19, 2026, separately from February 3 publication. Exact affected-version and first-fixed-release bounds were not established from reviewed primary sources.",
        "The underlying finding predates this article; 2026 labels the detailed educational publication. No bounty amount or independent exploit verification is claimed."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "mythicaldash-2026-payment-evidence-entitlement",
      "title": "MythicalDash: payment evidence must establish credit entitlement",
      "publisher": "MythicalDash",
      "authors": [],
      "primary_url": "https://github.com/MythicalLTD/MythicalDash/security/advisories/GHSA-qmh4-5v7g-42jq",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "business-logic",
        "authorization"
      ],
      "skillset_ids": [
        "approval-state-integrity",
        "integration-threat-modeling",
        "defensive-evidence-writing"
      ],
      "version": null,
      "summary": "GHSA-qmh4-5v7g-42jq concerns pending payment state being accepted as authority to grant account credit before provider-confirmed settlement. The account update was atomic, but that concurrency property did not establish entitlement. The advisory reports unpaid credit creation in a controlled deployment. The failed boundary is provisional application state becoming spendable value without trustworthy completion evidence.",
      "defensive_use": "Editorial lesson: separate a request to purchase, trustworthy settlement evidence, the authorized beneficiary and the committed entitlement. Atomic arithmetic protects a balance update; it cannot supply a missing business precondition. Make the evidence required for each state transition explicit, and retain uncertainty when a provider outcome is unavailable. The public June 3 commit adds authentication, ownership binding, a persisted provider reference, and fail-closed checks of paid status and expected amount before crediting. These are observed code changes, not independently verified deployment behavior. When assessing remediation, distinguish source changes, controlled negative results, packaged releases and adoption. Evidence writing should preserve what an experiment actually exercised rather than presenting setup privileges as ordinary customer capabilities.",
      "prerequisites": [
        "Payment lifecycle and application state-machine concepts",
        "Account authorization, database atomicity and cross-service evidence concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory, repository commit and release metadata."
      },
      "dates": {
        "published": {
          "value": "2026-06-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-06-07",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication, not remediation or software-release date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T17:22:43Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Advisory, public commit and current latest-release metadata reviewed read-only. No target testing, independent reproduction or production-loss verification."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/MythicalLTD/MythicalDash/security/advisories/GHSA-qmh4-5v7g-42jq",
          "title": "MythicalDash GHSA-qmh4-5v7g-42jq security advisory",
          "publisher": "MythicalDash",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T17:22:43Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "fix-commit",
          "url": "https://github.com/MythicalLTD/MythicalDash/commit/188d4c4ed80b8d364b0c4605a9e38ceaab746e39",
          "title": "MythicalDash payment-verification code change, commit 188d4c4",
          "publisher": "MythicalDash",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T17:22:43Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "latest-release-api",
          "url": "https://api.github.com/repos/MythicalLTD/MythicalDash/releases/latest",
          "title": "MythicalDash latest-release metadata at review",
          "publisher": "MythicalDash via GitHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T17:22:43Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The advisory lists versions through 3.5.4-aurora as affected and no patched version. It assigns CVE-2026-54608.",
        "The controlled demonstration used a seeded account, no working payment-provider credentials and a payment reference obtained from the database. It reports unpaid credits and a processed payment record, but does not independently complete the ordinary buyer checkout path. Actual hosting-resource consumption or production financial loss is not established.",
        "The June 3, 2026 commit is public code-change evidence. At review, the latest-release API still identifies 3.5.4-aurora, published February 16, 2026 at 20:53:17 UTC. Neither source establishes a released fix. Resource edition and edition-release date remain unknown.",
        "The advisory credits tonghuaroot as Reporter. NaysKutzu is the publishing account; no explicit article byline was identified, so authors remains empty. These roles are preserved separately from authorship."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "n8n-2026-dynamic-credential-object-authority",
      "title": "n8n Dynamic Credentials: authorize credential lifecycle operations",
      "publisher": "n8n",
      "authors": [],
      "primary_url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-2j5h-858j-5mpf",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "CVE-2026-54305 concerns authenticated Dynamic Credentials operations missing workflow and credential ownership or scope checks. Maintainers report unauthorized credential metadata access, OAuth identity replacement and token revocation. Subsequent integration execution may use the substituted identity; production exploitation is not established.",
      "defensive_use": "Apply object authorization consistently to discovery, authorization and revocation, including indirect workflow references. Maintainers list fixes in 1.123.55, 2.25.7 and 2.26.2. Restricting access to trusted users or disabling the feature is temporary mitigation, explicitly not full remediation.",
      "prerequisites": [
        "Basic federation and object-level authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-06-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication, not software patch release."
        },
        "source_displayed": {
          "value": "2026-06-10",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication, not software patch release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:49:44Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory reviewed; no immutable educational edition established."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-2j5h-858j-5mpf",
          "title": "Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints",
          "publisher": "n8n",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:49:44Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires an Enterprise instance with Dynamic Credentials enabled and an authenticated session, without requiring project membership or credential sharing.",
        "Jubke is the publishing account; Solidscripting and Har1sh-k are credited reporters. Article authorship is not established.",
        "Impact statements lack separate observed-versus-modeled demonstrations. Exfiltration and persistence remain maintainer-described consequences.",
        "Fixed versions apply within respective release lines; software release dates are not established.",
        "Distinct from the existing refresh-grant audience-binding resource."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "n8n-2026-ldap-account-linking-authority",
      "title": "n8n: directory-attribute authority in durable account linking",
      "publisher": "n8n",
      "authors": [
        "Jubke"
      ],
      "primary_url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-c545-x2rh-82fc",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-33665 describes local-account linkage that trusted a matching LDAP email attribute. The maintainer reports persistent access to the linked account, including administrator authority, even after the directory attribute changed back.",
      "defensive_use": "Editorial lesson: an identity association is a security grant with its own approval and revocation requirements. Attribute equality alone should not establish account ownership. Review claim provenance, linking consent and existing association cleanup independently. The maintainer identifies software versions 1.121.0 and 2.4.0 as fixes for their respective release lines.",
      "prerequisites": [
        "Basic understanding of authentication, account state and authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-03-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition date established; software fix versions are discussed separately."
        },
        "source_displayed": {
          "value": "2026-03-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:09:31Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory reviewed; no deployment assessment or independent reproduction performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-c545-x2rh-82fc",
          "title": "LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover",
          "publisher": "n8n",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:09:31Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires enabled LDAP authentication, which is non-default, and an authenticated directory user able to alter their own email attribute. This is a maintainer-described impact, not evidence of a production compromise.",
        "The advisory recommends temporary LDAP restriction or disabling and account-association review, but calls those measures incomplete. It does not establish automatic removal of previously incorrect links or a patch-release date.",
        "Jubke published the advisory. Credited reporters are weblover12, 34selen, B0RI, bde574786 and jh-hack. Original report date is not established. Learning prerequisites and design lessons are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "n8n-2026-refresh-grant-resource-binding",
      "title": "n8n: refreshed authority must remain bound to the consented resource",
      "publisher": "n8n",
      "authors": [
        "Matsuuu"
      ],
      "primary_url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-cw9w-vv67-hf73",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "identity",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "security-token-design",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "The maintainer reports that initial OAuth authorization preserved resource-specific consent, while refresh grants checked registration without preserving that binding. A client could consequently receive authority over another workflow accessible to the consenting user. This is a delegated-consent failure; the source does not establish access beyond that user’s underlying permissions or a production incident.",
      "defensive_use": "The stated repair retains the granted resource in refresh-token state and rejects conflicting resource choices. The maintainer also calls for renewed authorization after upgrading because older refresh tokens lack this binding; temporary restrictions are incomplete mitigation. Editorial lesson: review authorization invariants throughout a grant’s lifecycle, including migration of pre-fix state.",
      "prerequisites": [
        "OAuth grant, refresh, resource, and consent concepts",
        "Distinguishing a user’s permissions from the smaller authority delegated to a client"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer security advisory."
      },
      "dates": {
        "published": {
          "value": "2026-09-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication, not software patch release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition release established."
        },
        "source_displayed": {
          "value": "2026-09-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:10:39Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary maintainer evidence reviewed. No exploit reproduction, live testing, or independent patch verification performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-cw9w-vv67-hf73",
          "title": "Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution",
          "publisher": "n8n",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:10:39Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release-2382",
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n@2.38.2",
          "title": "n8n@2.38.2 release",
          "publisher": "n8n",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:10:39Z",
          "supports": [
            "dates"
          ]
        },
        {
          "id": "release-2377",
          "url": "https://github.com/n8n-io/n8n/releases/tag/n8n@2.37.7",
          "title": "n8n@2.37.7 release",
          "publisher": "n8n",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:10:39Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "CVE-2026-86073. The advisory credits bariskececi as reporter; Matsuuu is its publishing maintainer.",
        "Prerequisites include client registration, authenticated user consent for one protected workflow, and another identifiable workflow within that user’s execution permissions.",
        "The patched-version table lists 2.38.2 and 2.37.7, while prose says 2.38.1 and 2.37.7. No corrected affected interval is inferred.",
        "Official release pages date both 2.38.2 and 2.37.7 to September 2, 2026, separately from September 3 advisory publication; 2.38.2 is labeled pre-release. Release existence does not resolve the advisory inconsistency.",
        "No bounty is established. Learning prerequisites and general design guidance are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "ndss-2026-cross-device-consent-and-session-control",
      "title": "Cross-device authentication: bind informed consent to session authority",
      "publisher": "Internet Society / NDSS Symposium",
      "authors": [
        "Xin Zhang",
        "Xiaohan Zhang",
        "Huijun Zhou",
        "Bo Zhao"
      ],
      "primary_url": "https://www.ndss-symposium.org/ndss-paper/anchors-of-trust-a-usability-study-on-user-awareness-consent-and-control-in-cross-device-authentication/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "approval-state-integrity",
        "defensive-evidence-writing"
      ],
      "version": "NDSS 2026 proceedings; DOI 10.14722/ndss.2026.240656",
      "summary": "An evaluation of 27 services and a 100-participant user study examines missing context, explicit consent and post-login control in cross-device authentication. Conceptual boundary: an already trusted device may approve access on another device, but possession of that trusted session alone does not establish the user’s informed intent for the new session.",
      "defensive_use": "For an owned design, connect the approving interface to meaningful target-device and request context, a deliberate consent decision, and accessible session review and revocation. Verify that a revocation decision reaches the actual authorization checks. UI confirmation alone cannot establish backend enforcement.",
      "prerequisites": [
        "Cross-device login approval and session lifecycle",
        "Difference between interface consent and server-side authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Publisher page and full paper were publicly readable at review."
      },
      "dates": {
        "published": {
          "value": "2026-02",
          "precision": "month",
          "basis": "explicit",
          "source_id": "paper",
          "note": "Proceedings identifies the February 23–27, 2026 symposium; month describes that edition, not an established first online publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T06:50:31Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed publisher metadata and paper findings, discussion and limitations. Proceedings edition identified; no separate revision date established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.ndss-symposium.org/ndss-paper/anchors-of-trust-a-usability-study-on-user-awareness-consent-and-control-in-cross-device-authentication/",
          "title": "Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication",
          "publisher": "Internet Society / NDSS Symposium",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:50:31Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "paper",
          "url": "https://www.ndss-symposium.org/wp-content/uploads/2026-f656-paper.pdf",
          "title": "Publisher-hosted proceedings paper",
          "publisher": "Internet Society / NDSS Symposium",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:50:31Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The study documents implementation and user-expectation gaps, including six services without revocation controls. These are historical observations, not a present-day exposure inventory.",
        "The paper reports continued chat-history access in one revoked-session case; broad account-compromise risk is a consequence discussed by the authors, not a measured compromise rate across all 27 services.",
        "The main user study used videos and screenshots and primarily U.S. participants; a separate ten-person interactive study is supportive but small. Self-report and sampling limitations remain.",
        "Developer acknowledgments and roadmap commitments do not establish completed remediation. Context-specific interface patterns and broader validation remain future work.",
        "Published in NDSS 2026 proceedings; the paper acknowledges anonymous reviewers. This is not a protocol-wide proof or a claim that all cross-device authentication is insecure."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "nextjs-2026-response-metadata-representation-boundary",
      "title": "Next.js: response metadata must preserve representation boundaries",
      "publisher": "zhero_web_security",
      "authors": [
        "Rachid Allam (zhero;)",
        "inzo_"
      ],
      "primary_url": "https://zhero-web-sec.github.io/research-and-things/re-cache-excessive-reflection-type-confusion-and-0-click-sxss-on-nextjs",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "web-foundations",
        "interpreter-boundaries"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "cache-artifact-isolation"
      ],
      "version": null,
      "summary": "Researchers describe client-supplied metadata becoming authoritative response metadata through unusual middleware header copying. This changed how a dynamic App Router representation was interpreted; an external shared cache preserved the mismatch for later visitors. They report stored browser script execution in an anonymized production application. The core failure is a representation contract losing its integrity when request data controls response meaning.",
      "defensive_use": "Keep ownership of response interpretation with the component that creates the body. Next.js documentation warns that copying incoming headers into responses can override framework expectations and recommends selective forwarding. Editorial lesson: review body format, response metadata and cache variation as one contract. Data safe for one consumer may be unsafe for another; persistence does not repair that mismatch. An application review should distinguish intended upstream request metadata from browser-facing response metadata and document which layer owns each decision.",
      "prerequisites": [
        "HTTP request and response metadata, content negotiation and shared-cache concepts",
        "Basic server-rendered framework and browser interpretation concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public researcher article and supporting framework documentation."
      },
      "dates": {
        "published": {
          "value": "2026-06",
          "precision": "month",
          "basis": "explicit",
          "source_id": "research",
          "note": "The article displays June 2026; no publication day is established."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-06",
          "precision": "month",
          "basis": "explicit",
          "source_id": "research",
          "note": "The article displays June 2026; no publication day is established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T16:19:24Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Researcher publication and framework guidance read. The documentation supports the general boundary warning, not independent confirmation of the reported production outcomes."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://zhero-web-sec.github.io/research-and-things/re-cache-excessive-reflection-type-confusion-and-0-click-sxss-on-nextjs",
          "title": "Re:CACHE: Next.js response-reflection research",
          "publisher": "zhero_web_security",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T16:19:24Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "framework",
          "url": "https://nextjs.org/docs/app/api-reference/functions/next-response#next",
          "title": "NextResponse documentation: request forwarding and response headers",
          "publisher": "Next.js",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T16:19:24Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Exposure requires the described header-copying behavior, a dynamic representation and external caching. This is configuration-specific; the article does not establish a universal Next.js flaw.",
        "The reported effect still requires a visitor to load affected content. The publication supplies no independently corroborated vendor incident account, verified fixed version or remediation date.",
        "The unspecified five-figure award establishes neither an exact amount nor a currency. This resource does not qualify as an award-backed report."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "nextjs-server-client-data-security",
      "title": "Next.js data security: server authorization and client-visible data",
      "publisher": "Next.js / Vercel",
      "authors": [],
      "primary_url": "https://nextjs.org/docs/app/guides/data-security",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "untrusted-input-handling",
        "secure-parser-review",
        "secrets-containment"
      ],
      "version": null,
      "summary": "Explains how server rendering changes data-access assumptions. A dedicated server-side data layer can centralize authorization and expose only fields required by the interface. Server Actions need their own caller and resource checks; page visibility does not provide that protection. Server Action return values and properties passed to Client Components must be treated as client-visible contracts.",
      "defensive_use": "For an owned application, document where privileged data becomes renderable or serializable. Keep data access and permission checks together, validate action inputs, and minimize returned fields. Treat framework safeguards as additional protections around explicit authorization.",
      "prerequisites": [
        "React Server Components and Server Actions concepts",
        "Authentication, object authorization and serialization basics"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official public guidance was readable without an account at review time."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-08-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "The page explicitly labels this as its last-updated date; original publication was not established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:41:24Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the official page content. The review date does not establish publication or an immutable revision."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://nextjs.org/docs/app/guides/data-security",
          "title": "How to think about data security in Next.js",
          "publisher": "Next.js / Vercel",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:39:54Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The page is living framework guidance, not evidence that any deployed application is vulnerable.",
        "Taint APIs are experimental and supplement explicit data minimization; encrypted closures do not replace careful handling of sensitive data.",
        "A navigation version label was not treated as the version of this guidance."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "nhost-2026-provider-claim-verification-provenance",
      "title": "Nhost: provider adapters must preserve identity-claim evidence",
      "publisher": "Nhost",
      "authors": [
        "dbarrosop"
      ],
      "primary_url": "https://github.com/nhost/nhost/security/advisories/GHSA-6g38-8j4p-j3pr",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-41574 describes provider adapters converting email presence or fallback profile attributes into a verification claim. An account-linking consumer then treated that normalized claim as ownership evidence. The maintainer reports unauthorized identity merging and authenticated access to an existing account.",
      "defensive_use": "Editorial reasoning: normalization must retain the strength and origin of evidence. A nonempty identity attribute is not interchangeable with proof of mailbox control. Review adapter contracts and the account-linking decision together; rejecting absent or unverified evidence must remain consistent across providers. Official auth@0.49.1 release notes dated 2026-04-17 corroborate stricter provider email-verification handling.",
      "prerequisites": [
        "OAuth identity-provider claims and local account-linking concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-04-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-04-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource edition date established; software remediation is recorded separately."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:48:42Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and release notes reviewed; no independent reproduction or deployment assessment."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/nhost/nhost/security/advisories/GHSA-6g38-8j4p-j3pr",
          "title": "Account Takeover via OAuth Email Verification Bypass",
          "publisher": "Nhost",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:48:42Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/nhost/nhost/releases/tag/auth@0.49.1",
          "title": "Release auth@0.49.1",
          "publisher": "Nhost",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:39:59.794959Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        }
      ],
      "caveats": [
        "The advisory lists auth service versions before 0.49.1 as affected. Exposure depends on an affected provider adapter being enabled and an existing matching local identity. Provider-specific prerequisites differ; no universal OAuth-provider compromise is established.",
        "dbarrosop published the advisory; skoveit is credited as reporter. Technical claims are maintainer-reported, not independently reproduced.",
        "The advisory makes provider-specific assertions about Microsoft claims that were not independently corroborated; this record relies on the broader adapter-evidence boundary, not those assertions.",
        "Maintainer disclosure, not a peer-reviewed paper or an award-backed report. Software patch chronology is separate from resource edition metadata."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "nist-sp-800-162-attribute-authority-modeling",
      "title": "NIST SP 800-162: attribute authority and policy traceability",
      "publisher": "National Institute of Standards and Technology",
      "authors": [
        "Vincent C. Hu",
        "David Ferraiolo",
        "Rick Kuhn",
        "Adam Schnitzer",
        "Kenneth Sandlin",
        "Robert Miller",
        "Karen Scarfone"
      ],
      "primary_url": "https://csrc.nist.gov/pubs/sp/800/162/upd2/final",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "authorization",
        "identity"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "integration-threat-modeling"
      ],
      "version": "SP 800-162 (January 2014; updated August 2, 2019)",
      "summary": "Defines authorization in terms of subject, object, operation and environmental attributes evaluated against policy. Enterprise considerations connect business rules to machine-enforced decisions, attribute authorities and consistent meanings across organizations. Attribute maintenance, provenance and integrity are part of the authorization model rather than incidental metadata.",
      "defensive_use": "For an owned policy design, identify who may assert each attribute, how it is bound to its subject or object, and how changes reach decision points. Compare resulting permissions with the written policy.",
      "prerequisites": [
        "Basic understanding of access-control concepts"
      ],
      "prerequisites_basis": "publisher_explicit",
      "access": {
        "cost": "free",
        "note": "Official public guidance; no account required to read."
      },
      "dates": {
        "published": {
          "value": "2014-01",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Original publication month; distinct from later updates."
        },
        "version_released": {
          "value": "2019-08-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "publication",
          "note": "Errata update adds environment conditions to the ABAC trust-chain figure; not a new original publication."
        },
        "source_displayed": {
          "value": "2019-08-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Catalog identifies updates through this date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T01:41:34Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed the catalog and publication scope, audience, errata, attribute management and policy traceability sections; historical edition retained explicitly."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://csrc.nist.gov/pubs/sp/800/162/upd2/final",
          "title": "Guide to Attribute Based Access Control (ABAC) Definition and Considerations",
          "publisher": "National Institute of Standards and Technology",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T01:39:33Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "publication",
          "url": "https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-162.pdf",
          "title": "NIST SP 800-162: scope, audience, attribute management and policy traceability",
          "publisher": "National Institute of Standards and Technology",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T01:39:49Z",
          "supports": [
            "summary",
            "version",
            "dates",
            "prerequisites"
          ]
        }
      ],
      "caveats": [
        "Assumes subjects are bound to trusted identities; it does not comprehensively cover authentication or identity management.",
        "Historical conceptual guidance, not a product certification or a complete deployment checklist."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "nist-sp-800-190-container-isolation-guide",
      "title": "NIST SP 800-190: Application Container Security Guide",
      "publisher": "National Institute of Standards and Technology",
      "authors": [
        "Murugiah Souppaya",
        "John Morello",
        "Karen Scarfone"
      ],
      "primary_url": "https://csrc.nist.gov/pubs/sp/800/190/final",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "cloud-security",
        "supply-chain"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "dependency-provenance",
        "patch-verification"
      ],
      "version": "SP 800-190 (2017 final)",
      "summary": "A foundational model of container images, registries, orchestration, runtimes and host security. It explains shared-kernel risk, workload separation, constrained runtime permissions and lifecycle maintenance.",
      "defensive_use": "Build an owned environment’s boundary-and-responsibility map, then compare product-specific controls with current vendor guidance.",
      "prerequisites": [
        "Operating-system, networking and security expertise",
        "Familiarity with hypervisors and virtual machines"
      ],
      "prerequisites_basis": "publisher_explicit",
      "access": {
        "cost": "free",
        "note": "Official publication and PDF are publicly available."
      },
      "dates": {
        "published": {
          "value": "2017-09-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "catalog",
          "note": "Exact final-publication date from NIST document history; the PDF cover gives September 2017."
        },
        "version_released": {
          "value": "2017-09-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "catalog",
          "note": null
        },
        "source_displayed": {
          "value": "2017-09",
          "precision": "month",
          "basis": "explicit",
          "source_id": "catalog",
          "note": "Catalog publication label. The September 2020 planning note concerns a translation, not a new edition."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T17:52:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Historical 2017 final publication. Reviewed catalog, audience, executive summary, and container/runtime/host countermeasure sections; no claim of a new 2026 edition."
      },
      "sources": [
        {
          "id": "catalog",
          "url": "https://csrc.nist.gov/pubs/sp/800/190/final",
          "title": "NIST SP 800-190 publication catalog",
          "publisher": "NIST",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T17:52:00Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "publication",
          "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-190.pdf",
          "title": "NIST SP 800-190, audience and sections 4.4–4.5",
          "publisher": "NIST",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T17:52:00Z",
          "supports": [
            "summary",
            "prerequisites",
            "version"
          ]
        }
      ],
      "caveats": [
        "Historical architectural guidance; use current vendor documentation for versions and configuration details.",
        "The guide itself advises consulting newer material because container technology changes."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "nuxt-2026-island-component-selection-authority",
      "title": "Nuxt: island data must not acquire component-selection authority",
      "publisher": "Nuxt",
      "authors": [
        "danielroe"
      ],
      "primary_url": "https://github.com/nuxt/nuxt/security/advisories/GHSA-48hr-524c-v5w3",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "untrusted-input-handling",
        "authorization-modeling"
      ],
      "version": null,
      "summary": "The maintainer describes request-controlled island data reaching dynamic component selection through attribute inheritance. This permits unintended registered-component or native-element rendering. The boundary fails when input intended to configure an approved component instead chooses what component runs. The advisory expressly excludes arbitrary JavaScript execution through this vector.",
      "defensive_use": "Nuxt identifies 4.5.1 and 3.21.10 as patched for the common implicit-inheritance path. Explicit untrusted component selection remains application responsibility. Editorial lesson: define both accepted data and allowed interpretation at component boundaries; map external choices to a closed set of trusted components rather than treating strings as authority.",
      "prerequisites": [
        "Server-rendered applications and framework composition",
        "Trust-boundary modeling and application authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-07-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        },
        "source_displayed": {
          "value": "2026-07-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No educational-resource edition established; software patch chronology is separate."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:39:32Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory read. No live testing or independent patch execution performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/nuxt/nuxt/security/advisories/GHSA-48hr-524c-v5w3",
          "title": "Unauthorized Component Instantiation via Server Island Props in Nuxt",
          "publisher": "Nuxt",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:39:32Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "CVE-2026-71318. Requires active server islands and a dynamic-component consumer; installing a UI library alone is insufficient. Runtime template compilation is not required.",
        "Affected ranges: 3.1.0 through below 3.21.10, and 4.0.0 through below 4.5.1. Nuxt 2 is excluded. danielroe published the advisory.",
        "Patch-release dates were not established. Data exposure beyond unintended rendering depends on reachable components and is not demonstrated here.",
        "No bounty or production compromise is established. Learning prerequisites and generalized defensive reasoning are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "nuxt-2026-rendered-payload-cache-authorization",
      "title": "Nuxt: rendered-data caches must preserve request authorization",
      "publisher": "Nuxt",
      "authors": [
        "danielroe"
      ],
      "primary_url": "https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "cache-artifact-isolation",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-71316 documents an authorization mismatch between server-rendered HTML and extracted data. A shared path-keyed payload cache omitted requester identity and returned data before current-request guards. The maintainer confirms cross-user and unauthenticated disclosure while HTML remained protected. Application-specific secrets are possible contents, not independently observed production losses.",
      "defensive_use": "The advisory identifies 4.5.1 as fixed by limiting shared payload caching to prerendering and restoring runtime authorization. Official release notes corroborate the fix and recommend clearing upstream caches. Editorial lesson: treat each rendered representation as a separate disclosure boundary; correct HTML protection does not prove data-response protection.",
      "prerequisites": [
        "Server-side rendering and client data hydration",
        "Cache partitioning and request authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-07-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication, not software-release chronology."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established."
        },
        "source_displayed": {
          "value": "2026-07-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T08:19:27Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and official release reviewed. No reproduction or independent patch testing performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43",
          "title": "Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients",
          "publisher": "Nuxt",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:19:27Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/nuxt/nuxt/releases/tag/v4.5.1",
          "title": "Nuxt v4.5.1 release",
          "publisher": "Nuxt",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:19:27Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Exposure requires affected Nuxt 4.4.0–4.5.0, cached routes with runtime payload extraction, and user-specific server-rendered data. Nuxt 3.x is excluded by the advisory.",
        "The advisory credits quantumshiro as finder; danielroe is the publishing maintainer.",
        "No production incident or bounty amount established. Learning prerequisites and generalized review guidance are editorial.",
        "The software-release page displays July 27 without a year in the retrieved rendering. No exact software-release date is inferred; advisory publication is independently explicit."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "oauth2-proxy-2026-client-address-provenance-authority",
      "title": "OAuth2 Proxy: client-address provenance must precede authentication exemptions",
      "publisher": "OAuth2 Proxy",
      "authors": [],
      "primary_url": "https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-wr5q-7wxw-x568",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "version": null,
      "summary": "GHSA-wr5q-7wxw-x568 describes client-address metadata acquiring authority to waive authentication without verified transport-peer and intermediary provenance. The maintainer reports unauthenticated access within the authority already granted by configured address exemptions. This requires optional trusted-address exemptions, reverse-proxy mode and client-controlled address metadata reaching the decision. The educational focus is the authority of an exception path.",
      "defensive_use": "The v7.15.5 release describes transport-peer verification, bounded intermediary trust and safe failure when trusted-intermediary address metadata is missing or malformed. Upgrading alone is insufficient: compatibility defaults retain overly broad proxy trust. Deployments retaining exemptions must narrowly scope trusted intermediaries and ensure ingress establishes trustworthy address metadata. The advisory recommends removing the exemptions as a workaround. Editorial lesson: treat an authentication exception as an authorization mechanism with its own evidence requirements. Record who can assert each decision-relevant attribute, what authority it can unlock, and what happens when its provenance is unavailable. Patch verification must cover effective configuration as well as installed version; a code change cannot establish a trust boundary that deployment policy leaves universal.",
      "prerequisites": [
        "Reverse-proxy, transport-peer and forwarded-metadata concepts",
        "Authentication exemptions and attribute-based authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and official release notes."
      },
      "dates": {
        "published": {
          "value": "2026-10-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-10-01",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T16:42:14Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Advisory, release notes and release API metadata reviewed. This records maintainer statements, not independent patch testing; the educational resource edition remains unknown."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-wr5q-7wxw-x568",
          "title": "OAuth2 Proxy client-address authentication-exemption advisory GHSA-wr5q-7wxw-x568",
          "publisher": "OAuth2 Proxy",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T16:41:23Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/oauth2-proxy/oauth2-proxy/releases/tag/v7.15.5",
          "title": "OAuth2 Proxy v7.15.5 release notes",
          "publisher": "OAuth2 Proxy",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T16:40:59Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "release-metadata",
          "url": "https://api.github.com/repos/oauth2-proxy/oauth2-proxy/releases/tags/v7.15.5",
          "title": "OAuth2 Proxy v7.15.5 official release metadata",
          "publisher": "OAuth2 Proxy",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T16:41:23Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "Affected-version metadata lists 6.1.0 through 7.15.3, patched-version metadata says later than 7.15.4, and the advisory body names 7.15.5. This gap does not establish 7.15.4 as unaffected.",
        "The release API records v7.15.5 publication at 2026-10-01T09:05:48Z. This is software-release chronology, not the educational resource's edition date or proof of deployment remediation.",
        "The advisory credits gronke, SmylerMC, etsubu, SnailSploit and ihopenre-eng as reporters. Publishing account tuunit is not an established byline; authors remain unassigned.",
        "The sources establish neither universal deployment exposure, downstream account takeover, a production incident nor an award. The advisory lists no known CVE; unrelated release CVEs are not assigned to this record."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "obot-2026-oauth-audience-and-consent-boundaries",
      "title": "Obot: preserve delegated token audience and consent boundaries",
      "publisher": "Obot",
      "authors": [
        "thedadams"
      ],
      "primary_url": "https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "identity-lifecycle-review",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication; not software release date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned resource edition established; product fix versions are recorded below."
        },
        "source_displayed": {
          "value": "2026-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date beside the advisory publisher."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T08:39:25Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed maintainer advisory and corroborating project sources. No software executed or deployment tested."
      },
      "content_scope": "defensive_education",
      "summary": "GHSA-xwmw-prc4-v3cr describes MCP-delegated tokens accepted by broader application APIs because issuer validation did not establish audience authority. Client authorization also lacked explicit consent. The maintainer describes possible access to resources already available to the victim; this is bounded worst-case impact, not evidence of observed production compromise.",
      "defensive_use": "The maintainer identifies v0.23.0 as patched. Its release notes corroborate consent, narrower token routing and audience checks. Editorial lesson: verify issuer, intended recipient and permitted actions independently; consent alone cannot repair overbroad token acceptance.",
      "prerequisites": [
        "OAuth client registration, consent and token audience concepts",
        "Delegated authorization across application and MCP boundaries"
      ],
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-xwmw-prc4-v3cr",
          "title": "OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion",
          "publisher": "Obot",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:39:25Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/obot-platform/obot/releases/tag/v0.23.0",
          "title": "Obot v0.23.0 release notes",
          "publisher": "Obot",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:39:25Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "database-history",
          "url": "https://github.com/advisories/GHSA-xwmw-prc4-v3cr",
          "title": "GHSA-xwmw-prc4-v3cr publication history",
          "publisher": "GitHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:39:25Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "Publisher prerequisites: affected versions through v0.22.1, application authentication enabled, and interaction by an already signed-in victim. No preexisting attacker account is required.",
        "The maintainer credits EQSTLab as reporter. No award claim is made.",
        "GitHub records September 18, 2026 database publication and review separately from June 22 maintainer publication. The release page displays June 17 without a year in the retrieved text; no full software-release date is inferred.",
        "The reviewed sources do not establish automatic revocation of previously issued tokens after upgrade; historical exposure and remediation validation remain deployment-specific.",
        "Conceptual defensive summary only; public disclosure grants no testing authorization."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "open-webui-2026-connection-credential-capture",
      "title": "Open WebUI: credentials must bind to their destination connection",
      "publisher": "Open WebUI",
      "authors": [
        "doge-woof"
      ],
      "primary_url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-p78m-89r6-pgf7",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "ai-security"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "secrets-containment",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-87015 concerns late-bound connection state: tool callables retained their own headers but read a shared cookie variable after connection processing finished. A maintainer-described controlled observation confirmed unintended session-cookie forwarding. Connection-specific authentication choice therefore failed to constrain the credentials crossing an integration boundary.",
      "defensive_use": "Editorial lesson: treat destination, headers and cookies as one immutable request-authority context. Review capture semantics independently of configuration correctness. The advisory identifies 0.11.1 as fixed by binding cookies per connection. Credential isolation should survive changes in connection order.",
      "prerequisites": [
        "HTTP credentials, integration boundaries and secure data handling"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-09-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer publication date; distinct from database ingestion or patch release."
        },
        "source_displayed": {
          "value": "2026-09-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer publication date; distinct from database ingestion or patch release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational edition established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:19:06Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory reviewed; no software executed or deployment tested."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-p78m-89r6-pgf7",
          "title": "A user's session cookies are sent to tool servers configured for bearer authentication",
          "publisher": "Open WebUI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:19:06Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Affected versions are >=0.6.27 and <0.11.1. Requires multiple attached tool servers, including a session/system-OAuth connection; exposure depends on shared-state capture during connection processing. Tool servers are not configured by default.",
        "The recipient is an administrator-registered, partially trusted server. Impersonation, including administrator access, is a stated consequence of session-token disclosure; production compromise is not established.",
        "Classic298 is credited as reporter. Patch-release date is not established here."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "open-webui-2026-realtime-revocation-consistency",
      "title": "Open WebUI: revocation must cross HTTP and realtime boundaries",
      "publisher": "Open WebUI",
      "authors": [],
      "primary_url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-855v-hq7w-jmjw",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "security-token-design",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-59219 documents inconsistent session invalidation: HTTP authentication consulted revocation state, while realtime authentication checked only token signature and expiry. The reported local comparison shows revoked credentials rejected by HTTP but accepted for new realtime authentication. Cryptographic validity had been mistaken for continuing session authority.",
      "defensive_use": "Editorial lesson: model revocation as a shared invariant across every transport. The advisory identifies 0.10.0 as patched through shared revocation checks. Distinguish denial of new connections from termination of existing ones when reviewing remediation guarantees.",
      "prerequisites": [
        "JWT validity, session revocation and asynchronous transports"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-07-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer publication, not advisory-database ingestion or software release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational edition established."
        },
        "source_displayed": {
          "value": "2026-07-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication beside the publishing account."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:38:43Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer source reviewed; no software executed or deployment tested."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-855v-hq7w-jmjw",
          "title": "Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout",
          "publisher": "Open WebUI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:38:43Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Applies to Redis-backed versions 0.9.0 through versions before 0.10.0 and requires possession of an otherwise valid revoked token. Without Redis, per-token invalidation is unsupported by design.",
        "Realtime disclosure and impersonation are maintainer-described consequences; broader production exploitation is not established. Terminal access additionally depends on terminal configuration; HTTP remains protected.",
        "Existing-connection termination is not established. The advisory identifies doge-woof as the publishing account and credits huslayer826 as Reporter and Classic298 as Coordinator. The reviewed advisory provides no explicit article byline; these publication and credit roles do not establish article authorship. Separate from the catalog's role-claim provenance advisory."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "open-webui-2026-role-claim-provenance-and-revocation",
      "title": "Open WebUI: preserve role-policy meaning across identity flows",
      "publisher": "Open WebUI",
      "authors": [
        "doge-woof"
      ],
      "primary_url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-2rr4-q6pg-m5g3",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "identity-lifecycle-review",
        "patch-verification"
      ],
      "version": null,
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-09-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication; not software release date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately versioned resource edition established; product fix versions are recorded below."
        },
        "source_displayed": {
          "value": "2026-09-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date beside the advisory publisher."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T08:39:25Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed maintainer advisory and corroborating project sources. No software executed or deployment tested."
      },
      "content_scope": "defensive_education",
      "summary": "GHSA-2rr4-q6pg-m5g3 documents a shared-policy input mismatch: browser sign-in supplied identity-token claims, while token exchange supplied only provider user information. Missing role evidence preserved an old role. The maintainer reports local verification of continued access on 0.11.3 and rejection on 0.11.4; consequences beyond the prior role are not demonstrated.",
      "defensive_use": "Version 0.11.4 is identified as patched. The linked change and release notes corroborate expanded claim handling and rejection when role evidence cannot be read. Editorial lesson: sharing policy code is insufficient when callers provide different evidence; document claim provenance and make missing-evidence behavior explicit.",
      "prerequisites": [
        "OIDC claims and application-role mapping",
        "Account linking, role revocation and fail-closed policy behavior"
      ],
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-2rr4-q6pg-m5g3",
          "title": "Revoked users keep signing in via token exchange when roles are only in the ID token",
          "publisher": "Open WebUI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:39:25Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "earlier-advisory",
          "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-wvm9-9g5j-623f",
          "title": "Users denied by the OAuth role policy can still sign in via token exchange",
          "publisher": "Open WebUI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:39:25Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "patch",
          "url": "https://github.com/open-webui/open-webui/commit/10d1cfe6375f207acaa531e857edb575ded2cfc3",
          "title": "Role-claim handling remediation commit",
          "publisher": "Open WebUI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:39:25Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/open-webui/open-webui/releases/tag/v0.11.4",
          "title": "Open WebUI v0.11.4 release notes",
          "publisher": "Open WebUI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:39:25Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Publisher prerequisites: non-default token exchange and role management enabled, a non-wildcard allowed-role policy, roles absent from provider user information, and a previously linked account still able to receive valid provider tokens.",
        "The advisory covers 0.11.1 through 0.11.3. Prior access persists; no new account or privilege elevation is established. Browser sign-in remains policy-enforcing.",
        "The September 9 advisory identified 0.11.1 as fixing omitted role evaluation. The September 27 disclosure establishes that claim-source differences required further remediation; the earlier fix must not be presented as sufficient for this case.",
        "The primary advisory credits manus-pi as reporter and Classic298 for remediation. Its local-provider experiment does not independently verify every identity-provider configuration or deployed installation.",
        "The remedy addresses newly issued sessions; immediate invalidation of all previously issued sessions is not established by these sources. Resource publication and product patch release are distinct.",
        "Conceptual defensive summary only; public disclosure grants no testing authorization."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "openfga-2026-composed-policy-exclusion-integrity",
      "title": "OpenFGA: policy intersections must preserve explicit exclusions",
      "publisher": "OpenFGA",
      "authors": [
        "justincoh"
      ],
      "primary_url": "https://github.com/openfga/openfga/security/advisories/GHSA-g3pg-frfm-pr2m",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-61709 describes incorrect authorization-policy evaluation in user enumeration. Under a particular composition of wildcard membership, exclusion and intersection, a user denied by one policy component could reappear in the result through another component. The failed boundary is preservation of explicit denial when combining permission sets.",
      "defensive_use": "Editorial lesson: reason about policy results as complete sets, including exclusions, rather than merging positive membership alone. Design contained regression cases that compare composed policy outcomes with their intended semantics. The maintainer recommends OpenFGA 1.18.1 or later and lists Helm chart 0.3.10 as patched.",
      "prerequisites": [
        "Basic object-level authorization and policy-composition concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary advisory readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-07-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed by the primary maintainer advisory."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-07-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed by the primary maintainer advisory."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:19:23Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary maintainer advisory reviewed. No live testing, independent reproduction or deployment verification performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/openfga/openfga/security/advisories/GHSA-g3pg-frfm-pr2m",
          "title": "OpenFGA Improper Policy Enforcement",
          "publisher": "OpenFGA",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:19:23Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Applies when an application relies on ListUsers and its model combines a wildcard-based exclusion with an intersected relation that explicitly grants the excluded user. This does not establish that all models or authorization APIs are affected.",
        "The advisory establishes an incorrect result; downstream unauthorized disclosure depends on application use. No production incident or independently verified impact is reported.",
        "Published July 16, 2026 by justincoh; reporter 5ud0er is credited. Affected OpenFGA versions are listed through 1.18.0, Helm charts through 0.3.9. Patch release dates and resource-edition dates are not established."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "openfga-authorization-query-freshness",
      "title": "OpenFGA query consistency: authorization decisions need sufficiently fresh state",
      "publisher": "OpenFGA",
      "authors": [],
      "primary_url": "https://openfga.dev/docs/interacting/consistency",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "concurrency-reasoning"
      ],
      "version": null,
      "summary": "Authorization correctness includes the age of relationship state used for a decision. OpenFGA documents a latency-oriented mode that can reuse cached results and a higher-consistency mode that bypasses the cache. With caching enabled, an immediate permission check may miss a relationship update.",
      "defensive_use": "Editorial lesson: specify when permission changes must become observable and align decision freshness with that requirement. Review cache invalidation and performance assumptions together; a newly issued request does not necessarily use newly changed authorization state.",
      "prerequisites": [
        "Relationship-based authorization and cache consistency concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official implementation guidance."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication and edition release are not established."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication and edition release are not established."
        },
        "source_displayed": {
          "value": "2026-09-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Displayed last-modified date, not original publication."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T17:59:50Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Official documentation reviewed; no deployment or performance testing."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://openfga.dev/docs/interacting/consistency",
          "title": "Query Consistency Modes",
          "publisher": "OpenFGA",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T17:59:50Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The documentation says caching is disabled by default. Do not assume every deployment returns cached authorization decisions.",
        "Its illustrative timestamp branch appears inconsistent with the prose; this record does not reproduce or endorse that example.",
        "Consistency tokens are described as future work. This guidance establishes neither a deployment-specific freshness guarantee nor evidence of an incident."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "openid-fapi-2-api-authorization-profile",
      "title": "FAPI 2.0 Security Profile",
      "publisher": "OpenID Foundation",
      "authors": [
        "Daniel Fett",
        "Dave Tonge",
        "Joseph Heenan"
      ],
      "primary_url": "https://openid.net/specs/fapi-security-profile-2_0-final.html",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "security-token-design",
        "integration-threat-modeling"
      ],
      "version": "2.0 Final",
      "summary": "Defines a high-security OAuth profile with coordinated requirements for confidential clients, authorization servers, and resource servers. Connects sender-constrained tokens and authorization-request integrity with the separate requirement to evaluate whether a token’s authority is sufficient for each protected resource.",
      "defensive_use": "Map the ownership of token validation, issuer trust, client authentication, and resource-access decisions across an owned API integration. Keep protocol conformance distinct from application-specific authorization.",
      "prerequisites": [
        "OAuth roles and authorization-code flows",
        "Public-key client authentication and token validation"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official specification readable without an account at review time."
      },
      "dates": {
        "published": {
          "value": "2025-02-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publication date of this RFC or final specification."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:40:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed this identified edition and its relevant design and security sections. Retrieval date is separate from publication; later revisions or errata may exist."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://openid.net/specs/fapi-security-profile-2_0-final.html",
          "title": "FAPI 2.0 Security Profile",
          "publisher": "OpenID Foundation",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:40:00Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Public clients are outside this profile’s scope.",
        "Security claims depend on the stated model and complete implementation; this record is not certification."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "outline-2026-webhook-revocation-lifecycle",
      "title": "Outline: integration authority must end with its owning account",
      "publisher": "Outline",
      "authors": [
        "tommoor"
      ],
      "primary_url": "https://github.com/outline/outline/security/advisories/GHSA-33jq-x32c-3ccw",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "identity",
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "authorization-modeling"
      ],
      "version": null,
      "summary": "GHSA-33jq-x32c-3ccw describes webhook authority surviving deletion of its creator. Account cleanup omitted webhook subscriptions, while delivery trusted their enabled state. The maintainer-published report describes a local demonstration of document content delivery after the administrator account was deleted.",
      "defensive_use": "Editorial lesson: revocation must cover durable integrations and every terminal account state, with delivery-time checks as defense in depth. The advisory identifies 1.8.0 as patched. Its proposed cleanup changes are recommendations, not evidence of the implemented patch.",
      "prerequisites": [
        "Basic server-side authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public disclosure readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-06-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-06-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:59:36Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Public primary disclosure reviewed; deployed remediation and source immutability were not established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://github.com/outline/outline/security/advisories/GHSA-33jq-x32c-3ccw",
          "title": "Webhook subscription persists after creator's account deletion",
          "publisher": "Outline",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:59:36Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires a webhook previously configured by an administrator, followed by account deletion and a matching document event. The demonstrated deployment used 0.86.0; the maintainer lists versions through 1.7.1 as affected.",
        "Continued delivery was demonstrated locally; no production incident, measured duration or customer exposure is established. Persistent exposure is the report’s inference from absent expiry and revalidation.",
        "Published June 6, 2026 by tommoor, with dizconnectz credited as reporter. Publication does not establish the release date of 1.8.0. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-account-recovery-state-integrity",
      "title": "OWASP Forgot Password",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Forgot_Password_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "identity",
        "business-logic"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "security-token-design",
        "concurrency-reasoning"
      ],
      "version": null,
      "summary": "Explains account-bound recovery challenges, limited lifetime and reuse, consistent responses, attempt controls, notifications and post-reset session handling.",
      "defensive_use": "Document recovery-state invariants and ensure recovery cannot silently weaken the account’s normal authentication requirements.",
      "prerequisites": [
        "Basic authentication and session concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official guidance."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T16:59:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Living guidance; original publication and latest-update dates were not established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Forgot_Password_Cheat_Sheet.html",
          "title": "Forgot Password Cheat Sheet",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T16:59:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Password reset and multifactor recovery are distinct security decisions."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-asvs-5-security-verification-standard",
      "title": "OWASP Application Security Verification Standard (ASVS)",
      "publisher": "OWASP Foundation",
      "authors": [],
      "primary_url": "https://owasp.org/projects/asvs",
      "resource_type_id": "security-standard",
      "topic_ids": [
        "verification"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "version": "5.0.0",
      "summary": "Versioned requirements for secure development and reviewing web-application security controls. Useful for turning lessons from disclosures into traceable acceptance criteria and regression coverage.",
      "defensive_use": "Select applicable requirements for an owned application, retain the versioned identifiers, and record evidence for each control.",
      "prerequisites": [
        "Basic web-application architecture",
        "Familiarity with authentication and authorization",
        "A defined review scope"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": "2025-05-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": "Official GitHub release metadata gives published_at 2025-05-30T09:35:31Z; this is a version release, not the homepage publication."
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T14:50:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Review records accessible official guidance as of this date; living content and current versions may change."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://owasp.org/projects/asvs",
          "title": "OWASP Application Security Verification Standard (ASVS)",
          "publisher": "OWASP Foundation",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T14:50:00Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/OWASP/ASVS/releases/tag/v5.0.0_release",
          "title": "ASVS 5.0.0 release",
          "publisher": "OWASP",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T14:50:00Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-authorization-cheat-sheet",
      "title": "Authorization Cheat Sheet",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "cloud-iam-review"
      ],
      "version": null,
      "summary": "Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.",
      "defensive_use": "Document which identities may perform which operations on each resource and check implementation and tests against that policy.",
      "prerequisites": [
        "Authentication versus authorization",
        "Application roles and resource ownership",
        "Basic server-side development"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T14:50:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Review records accessible official guidance as of this date; living content and current versions may change."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html",
          "title": "Authorization Cheat Sheet",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T14:50:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-browser-message-trust-boundaries",
      "title": "HTML5 Security Cheat Sheet: Web Messaging",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/HTML5_Security_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "untrusted-input-handling",
        "authorization-modeling",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "OWASP explains origin checks, expected message formats and treating exchanged content as data. These controls address different assumptions at browser communication boundaries.",
      "defensive_use": "Document the expected sender, operation, recipient and permitted data for browser messages. Review identity checks, data validation, application authorization and rendering safety separately in owned application designs.",
      "prerequisites": [
        "Basic browser origin and document concepts",
        "Familiarity with event-driven JavaScript"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T19:49:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Official Web Messaging guidance and related communication sections reviewed. No original publication or version date is stated; this catalog entry focuses on messaging rather than claiming a review of every HTML5 topic."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/HTML5_Security_Cheat_Sheet.html",
          "title": "HTML5 Security Cheat Sheet: Web Messaging",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T19:49:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Living guidance; review supported browser behavior and application context before implementation.",
        "Origin and format validation do not by themselves define which business operations or disclosures are authorized."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-error-response-data-minimization",
      "title": "Error Handling Cheat Sheet",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Error_Handling_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "error-response-design",
        "secure-parser-review"
      ],
      "version": null,
      "summary": "OWASP guidance on centralized handling of unexpected failures, generic client-facing responses and server-side diagnostic records that do not reveal implementation details to clients.",
      "defensive_use": "Define separate public-error and internal-diagnostic contracts, then review ordinary failure handling in owned application code. Keep logging controls separate from response formatting.",
      "prerequisites": [
        "Basic HTTP response semantics",
        "Server-side exception handling"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T18:24:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Official introduction, objective and global-error-handler guidance reviewed. No original publication or version date is stated."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Error_Handling_Cheat_Sheet.html",
          "title": "Error Handling Cheat Sheet",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T18:24:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Living guidance; framework examples should be checked against the application’s supported runtime version.",
        "This resource concerns response disclosure; it does not by itself prove that authorization is preserved in privileged fallback paths."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-llm-output-consumer-trust",
      "title": "OWASP LLM05:2025: generated-output consumer trust",
      "publisher": "OWASP Gen AI Security Project",
      "authors": [],
      "primary_url": "https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "ai-security",
        "web-foundations"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "untrusted-input-handling",
        "integration-threat-modeling"
      ],
      "version": "LLM05:2025",
      "summary": "Explains why model-generated content remains untrusted when passed to browsers, databases or backend functions. The relevant boundary is the consuming component: plausible model text must not acquire executable meaning or greater authority merely because an application generated it. Distinguishes unsafe downstream handling from general reliance on answer accuracy.",
      "defensive_use": "Map each output consumer in an owned AI application to its validation and encoding contract. Prefer parameterized database operations and context-aware encoding, with monitoring and browser policy controls as supplementary layers.",
      "prerequisites": [
        "Basic LLM application data flow",
        "Context-sensitive encoding and separation of data from executable interpretation"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official public guidance was readable without an account at review time."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:41:24Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the official page content. The review date does not establish publication or an immutable revision."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/",
          "title": "LLM05:2025 Improper Output Handling",
          "publisher": "OWASP Gen AI Security Project",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:40:03Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "The 2025 designation is an edition identifier, not a verified publication date.",
        "The source contains attack scenarios; this record retains only trust-boundary and remediation concepts.",
        "This category describes possible failure modes rather than current exposure of a particular product."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-llm-prompt-injection-prevention",
      "title": "LLM Prompt Injection Prevention Cheat Sheet",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "ai-security"
      ],
      "skillset_ids": [
        "ai-authority-boundaries",
        "integration-threat-modeling",
        "untrusted-input-handling"
      ],
      "version": null,
      "summary": "Defense-in-depth guidance for LLM applications that consume untrusted content or invoke tools. Covers data provenance, least privilege, action authorization, monitoring, and the limitations of guardrails.",
      "defensive_use": "Review permissions and action boundaries around an owned AI integration; treat filters and model-based checks as partial defenses rather than guarantees.",
      "prerequisites": [
        "LLM application and tool-call basics",
        "Trust boundaries",
        "An understanding of the application's data and permissions"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T14:50:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Review records accessible official guidance as of this date; living content and current versions may change."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html",
          "title": "LLM Prompt Injection Prevention Cheat Sheet",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T14:50:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Includes attack examples; this collection uses it as a defensive-design reference",
        "Guidance evolves and individual examples require contextual evaluation"
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-rag-retrieval-permission-boundaries",
      "title": "OWASP LLM08:2025: retrieval permissions and knowledge provenance",
      "publisher": "OWASP Gen AI Security Project",
      "authors": [],
      "primary_url": "https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "ai-security",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "ai-authority-boundaries",
        "integration-threat-modeling"
      ],
      "version": "LLM08:2025",
      "summary": "Examines security assumptions around retrieval-augmented generation, including access to embeddings, cross-context disclosure and integrity of imported knowledge. Shared retrieval infrastructure must preserve the distinctions between users and data classifications. Source validation and retrieval records help explain which knowledge entered a response and whether access was appropriate.",
      "defensive_use": "For an owned RAG design, document dataset partitions and permission-aware retrieval, preserve source classifications when combining knowledge, and review ingestion integrity. Record retrieval events so confidentiality and provenance decisions remain reviewable.",
      "prerequisites": [
        "Basic concepts of embeddings, vector stores and retrieval-augmented generation",
        "User, group and tenant access-control models"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official public guidance was readable without an account at review time."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:41:24Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the official page content. The review date does not establish publication or an immutable revision."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/",
          "title": "LLM08:2025 Vector and Embedding Weaknesses",
          "publisher": "OWASP Gen AI Security Project",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:40:03Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "The 2025 designation is an edition identifier; publication and latest-update dates were not established.",
        "This record focuses on permissions and provenance; it does not reproduce the source’s attack scenarios or quantify embedding reconstruction risk.",
        "RAG grounding can improve relevance without establishing that retrieved content is authorized or trustworthy."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-secure-code-review-methodology",
      "title": "OWASP Secure Code Review: baseline and change-focused review",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Secure_Code_Review_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "verification",
        "business-logic"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "authorization-modeling",
        "defensive-evidence-writing"
      ],
      "version": null,
      "summary": "Explains how whole-codebase reviews and change-focused reviews answer different assurance questions. Connects architecture, business requirements and existing findings to manual examination of data movement, control placement and workflow state. Review documentation records the inspected version, coverage and remediation decisions.",
      "defensive_use": "For an owned codebase, document the review boundary and trace a selected security requirement through relevant code and tests. Record unsupported assumptions and unreviewed paths rather than claiming complete coverage.",
      "prerequisites": [
        "Ability to read the application language and framework conventions",
        "Understanding of data flow, trust boundaries and the intended business rules"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official public guidance; no account required to read."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T01:41:34Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the current official guidance. No publication, release or last-update date was established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Secure_Code_Review_Cheat_Sheet.html",
          "title": "OWASP Secure Code Review: baseline and change-focused review",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T01:39:33Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Pattern matches alone do not establish a defect; contextual review remains necessary.",
        "The source includes command examples and testing suggestions; this record retains review methodology only."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-security-logging-evidence-quality",
      "title": "OWASP Logging: trustworthy and minimal application evidence",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "verification",
        "reporting"
      ],
      "skillset_ids": [
        "defensive-evidence-writing",
        "secrets-containment",
        "untrusted-input-handling"
      ],
      "version": null,
      "summary": "Explains how application events support investigation through consistent context, interaction identifiers, outcomes and confidence information. Distinguishes event occurrence from recording time and treats cross-boundary event data as untrusted. Evidence quality also depends on data minimization, access restrictions, integrity protection and reliable logging behavior.",
      "defensive_use": "Using synthetic events in an owned application, review whether records can explain a decision without exposing credentials or personal data. Document correlation gaps, timestamp uncertainty and what the logs cannot prove.",
      "prerequisites": [
        "Basic familiarity with application events and structured logs",
        "Understanding of sensitive-data handling and access controls"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official public guidance; no account required to read."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T01:41:34Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the current official guidance. No publication, release or last-update date was established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html",
          "title": "OWASP Logging: trustworthy and minimal application evidence",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T01:39:33Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Logging does not automatically provide independent proof or non-repudiation.",
        "Collection and retention must match the authorized purpose; more recorded data is not necessarily better evidence."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-server-request-destination-boundaries",
      "title": "OWASP Server-Side Request Forgery Prevention",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "web-foundations",
        "cloud-security"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "secure-parser-review",
        "untrusted-input-handling",
        "secrets-containment"
      ],
      "version": null,
      "summary": "Explains destination validation and network isolation for server-initiated requests, distinguishing fixed trusted destinations from services that need broader external access.",
      "defensive_use": "Review owned-service destination policy, parser consistency, redirect behavior and independent egress restrictions.",
      "prerequisites": [
        "Basic knowledge of web requests and application/network boundaries"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official guidance."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T16:29:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Living guidance; publication and update dates were not established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html",
          "title": "Server-Side Request Forgery Prevention Cheat Sheet",
          "publisher": "OWASP",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T16:29:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "The destination-policy design depends on business requirements. Metadata protections complement application validation and network isolation."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-session-privilege-transition-integrity",
      "title": "OWASP Session Management: privilege-transition integrity",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "security-token-design",
        "authorization-modeling"
      ],
      "version": null,
      "summary": "Distinguishes application-issued session identifiers from client-selected values. Explains renewing identifiers at login and other privilege changes, retiring previous identifiers, and separating anonymous tracking from authenticated session authority. When several cookies represent one session, their relationship also requires validation.",
      "defensive_use": "Model login and privilege changes as explicit session-state transitions, with server-controlled identity and authority bindings. Document which credentials represent anonymous and authenticated state and how superseded state loses authority.",
      "prerequisites": [
        "Basic HTTP cookie and authentication concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official guidance."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T22:32:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Living guidance; publication and version dates were not established. Review time does not imply a new edition or software release."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html",
          "title": "Session Management Cheat Sheet",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T22:32:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Renewing a session identifier does not establish authorization for every resource or action; access decisions remain a separate responsibility.",
        "Official implementation guidance, not a product-specific finding, current-exposure claim or testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-threat-modeling-assumptions-and-validation",
      "title": "OWASP Threat Modeling: system assumptions and mitigation validation",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "verification",
        "business-logic"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "authorization-modeling",
        "defensive-evidence-writing"
      ],
      "version": null,
      "summary": "Presents an iterative design-review process linking a system model to potential threats, agreed responses and validation. Data-flow diagrams expose trust boundaries and dependencies; structured prompts help identify missing assumptions. Mitigations become measurable requirements, and accepted residual risks remain documented as the system changes.",
      "defensive_use": "For an owned design, write a bounded hypothesis about a missing security guarantee, identify the assumption behind it, and specify evidence that would support or refute it. Review the model with relevant stakeholders.",
      "prerequisites": [
        "Basic application architecture and security concepts",
        "Access to an accurate, authorized description of the system and business workflow"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official public guidance; no account required to read."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T01:41:34Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the current official guidance. No publication, release or last-update date was established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html",
          "title": "OWASP Threat Modeling: system assumptions and mitigation validation",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T01:39:33Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "A modeled threat is a hypothesis, not evidence of an implemented vulnerability.",
        "No single modeling technique covers every concern; the source recommends stating scope and methodological gaps."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "owasp-transaction-authorization-state-integrity",
      "title": "OWASP Transaction Authorization",
      "publisher": "OWASP Cheat Sheet Series",
      "authors": [],
      "primary_url": "https://cheatsheetseries.owasp.org/cheatsheets/Transaction_Authorization_Cheat_Sheet.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "business-logic",
        "authorization"
      ],
      "skillset_ids": [
        "approval-state-integrity",
        "concurrency-reasoning",
        "authorization-modeling",
        "security-token-design"
      ],
      "version": null,
      "summary": "Explains operation-specific approval: show significant transaction details, preserve authorized data, enforce valid state transitions and recheck authorization at execution.",
      "defensive_use": "Model an owned workflow’s approval states, expiration and invalidation rules, and relate each transition to a server-side invariant.",
      "prerequisites": [
        "Authentication versus operation authorization",
        "Basic application state-machine concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public official guidance."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T16:39:51Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Living guidance; original publication and latest-update dates were not established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://cheatsheetseries.owasp.org/cheatsheets/Transaction_Authorization_Cheat_Sheet.html",
          "title": "Transaction Authorization Cheat Sheet",
          "publisher": "OWASP Cheat Sheet Series",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T16:39:51Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Approval controls must match the application’s risk and workflow. This reference does not prescribe financial or legal policy."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "pac4j-2026-token-authenticity-enforcement",
      "title": "pac4j JWT validation: confidentiality does not establish authenticity",
      "publisher": "CodeAnt AI",
      "authors": [
        "Amartya Jha"
      ],
      "primary_url": "https://codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "security-token-design",
        "identity-lifecycle-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "Research on CVE-2026-29000 describes an authentication boundary failure: successful decryption could allow claims to become an authenticated profile without mandatory signature validation. The researcher reports arbitrary identity and role acceptance in a library-level demonstration on 6.0.3; production compromise is not established.",
      "defensive_use": "Treat authenticity checks as mandatory, fail-closed prerequisites for profile creation. Review all accepted token representations. The maintainer confirms remediation and directs upgrades to 4.5.9, 5.7.9 or 6.3.3 and newer within those release lines.",
      "prerequisites": [
        "Basic authentication and access-control concepts",
        "Familiarity with application trust boundaries"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-03-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-03-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T06:19:33Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary sources reviewed; no immutable article revision established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key",
          "title": "CVE-2026-29000: pac4j-jwt Auth Bypass PoC With a Public Key",
          "publisher": "CodeAnt AI",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:19:33Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer",
          "url": "https://www.pac4j.org/blog/security-advisory-pac4j-jwt-jwtauthenticator.html",
          "title": "Security advisory for pac4j-jwt (JwtAuthenticator)",
          "publisher": "pac4j",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:19:33Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "The demonstrated configuration uses RSA-encrypted JWTs with signature and encryption configuration; exposure cannot be inferred from any pac4j dependency alone.",
        "Application-specific consequences depend on how authenticated claims map to authorization.",
        "The maintainer confirms the issue and research credit but withholds technical details; the detailed mechanism remains researcher evidence.",
        "Article publication is separate from reporting and patch events. The article describes February 28 private disclosure and patches by March 2, 2026; exact version-release dates are not recorded here."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "parse-server-2026-upload-metadata-consumer-boundary",
      "title": "Parse Server: preserve safe file interpretation across storage and browsers",
      "publisher": "Parse Community",
      "authors": [],
      "primary_url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "GHSA-r899-h629-j84r describes inconsistent interpretation of uploaded-file metadata across admission, storage and browser consumption. The maintainer reports stored cross-site scripting when unsupported filename types retained invalid media-type metadata. The affected storage configurations preserved that metadata; default GridFS is explicitly unaffected.",
      "defensive_use": "The maintainer recommends corrected versions, application-specific file allowlists, origin separation for uploads and storage-layer anti-sniffing policy. Editorial lesson: admission checks and delivery behavior form one security contract. A successful upload validation result alone does not establish that later consumers will treat the object as inert data.",
      "prerequisites": [
        "Basic web upload handling and server-side validation",
        "Content-type interpretation and processing lifecycle concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and remediation references."
      },
      "dates": {
        "published": {
          "value": "2026-06-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition established. Software fix chronology appears in caveats."
        },
        "source_displayed": {
          "value": "2026-06-25",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed on the advisory."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T12:19:32Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed maintainer sources and the merged version-9 patch to qualify configuration-dependent validation. The version-8 diff was not independently inspected. No reproduction or patch testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/parse-community/parse-server/security/advisories/GHSA-r899-h629-j84r",
          "title": "Stored XSS via malformed Content-Type bypassing file upload extension blocklist",
          "publisher": "Parse Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:09:10Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "remediation-v9",
          "url": "https://github.com/parse-community/parse-server/pull/10521",
          "title": "Parse Server 9 remediation, pull request 10521",
          "publisher": "Parse Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:09:10Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "remediation-v8",
          "url": "https://github.com/parse-community/parse-server/pull/10523",
          "title": "Parse Server 8 remediation, pull request 10523",
          "publisher": "Parse Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:09:10Z",
          "supports": [
            "version",
            "dates"
          ]
        },
        {
          "id": "release-v9",
          "url": "https://github.com/parse-community/parse-server/releases/tag/9.10.0",
          "title": "Parse Server 9.10.0 release",
          "publisher": "Parse Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:10:36Z",
          "supports": [
            "version",
            "dates"
          ]
        },
        {
          "id": "v9-merged-patch",
          "url": "https://github.com/parse-community/parse-server/commit/cce91e554818492d1b153c46dc3b91fa6e0309bc",
          "title": "Version-9 merged metadata-validation patch and configuration scope",
          "publisher": "Parse Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:19:32Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Requires upload permission, a storage/delivery configuration retaining supplied metadata, and another user opening the uploaded object. Browser-side script execution is maintainer-reported; production exploitation, account takeover and server compromise are not established.",
        "The advisory lists affected ranges as <= 8.6.83 and >= 9.0.0, < 9.10.0-alpha.2. It identifies 8.6.84 and 9.10.0-alpha.2 as patched.",
        "The version-8 and version-9 remediation records show June 25, 2026 merges and releases; the version-9 stable release 9.10.0 is dated July 13, 2026. These are software events, not educational-resource editions.",
        "The advisory header identifies mtrezza as the publisher, and Credits lists CyberKareem as Finder and mtrezza as Coordinator. The reviewed advisory provides no explicit article-author byline, so the author field is left empty. No CVE is listed on the reviewed advisory.",
        "The version-9 correction validates supplied media types for unrecognized filename extensions when extension filtering is enabled; disabling that filtering also disables this validation. Well-formed custom types remain subject to configured restrictions. This does not establish that all accepted content is harmless.",
        "Learning prerequisites and the generalized consumer-contract lesson are editorial. No award claim is made."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "payload-2026-local-api-caller-authority",
      "title": "Payload: request adapters must retain caller-level authorization",
      "publisher": "jhb-software / Payload plugins",
      "authors": [],
      "primary_url": "https://github.com/jhb-software/payload-plugins/security/advisories/GHSA-4qpv-39hg-f7fx",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-59965 describes authenticated plugin endpoints invoking a privileged server interface without preserving collection-level authorization. Payload's Local API skips access checks by default, so a session check alone did not establish permission for selected upload documents. The conceptual failure is a request adapter inheriting trusted-server authority instead of retaining the caller's permissions.",
      "defensive_use": "Treat every request-to-server-API adapter as an authority boundary. Explicitly preserve the requesting actor and require the relevant collection policy for both reads and changes. Separate permission to use a feature from permission to act on its underlying data, and distinguish the collections a plugin manages from those a particular caller may access. These are editorial design-review objectives; the presence of a policy definition does not establish that an operation evaluates it.",
      "prerequisites": [
        "Authentication versus operation-specific authorization",
        "Server-side API defaults, caller context and collection access policies"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory, official framework documentation and release evidence."
      },
      "dates": {
        "published": {
          "value": "2026-06-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Publication of the selected advisory."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition is established."
        },
        "source_displayed": {
          "value": "2026-06-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T18:24:39Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Advisory, framework documentation and official release metadata read. This is source review, not independent reproduction or a current deployment assessment."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/jhb-software/payload-plugins/security/advisories/GHSA-4qpv-39hg-f7fx",
          "title": "Alt Text Endpoint Authorization Bypass via Payload Local API overrideAccess Omission",
          "publisher": "jhb-software / Payload plugins",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T18:22:57Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "framework",
          "url": "https://payloadcms.com/docs/local-api/overview",
          "title": "Payload Local API documentation",
          "publisher": "Payload",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T18:23:39Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "release",
          "url": "https://api.github.com/repos/jhb-software/payload-plugins/releases/tags/alt-text%400.8.0",
          "title": "Official alt-text 0.8.0 release notes and metadata",
          "publisher": "jhb-software / Payload plugins via GitHub",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T18:23:10Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The issue requires the affected alt-text plugin, an authenticated caller and collection policies that would otherwise deny the requested access. It is not an unauthenticated access claim.",
        "The advisory reports unauthorized upload-document reads and changes to alt text and keywords; this does not establish unrestricted field writes. Its supplied demonstration uses the real plugin handler with a mocked Payload framework, not a complete deployed stack. Production compromise, account takeover and independent reproduction are not established here.",
        "The advisory lists plugin versions before 0.8.0 as affected and 0.8.0 as patched. This historical minimum is not a comprehensive current security guarantee.",
        "The official 0.8.0 release notes describe reads and writes under the requesting user's collection access rules, plus rejection of collections outside plugin management. Release metadata records June 21, 2026 at 11:45:15 UTC; that software-release time is separate from the unknown resource-edition date.",
        "The advisory credits EQSTLab as Reporter and 232-323 as Finder. jhb-dev is the publishing account, not an explicit article byline, so authors remains empty. No individual award is established by these sources."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "paymenter-2026-refund-transition-atomicity",
      "title": "Paymenter: refund entitlement and ledger changes need one atomic transition",
      "publisher": "Paymenter",
      "authors": [],
      "primary_url": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-5gmm-hjfj-8ff7",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "business-logic",
        "authorization"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "approval-state-integrity",
        "patch-verification"
      ],
      "version": null,
      "summary": "The maintainer traces duplicate downgrade credits to an eligibility check separated from the later balance change, without transactional isolation. A pending-operation guard did not protect the whole transition. The failed invariant was one legitimate refund per service downgrade.",
      "defensive_use": "Editorial lesson: model refund eligibility, transition identity and ledger mutation as one atomic decision. Local regression checks should establish that repeated or overlapping processing cannot mint additional entitlement. The advisory identifies 1.5.7 as patched; its release notes explicitly link the fix.",
      "prerequisites": [
        "Basic application state machines, authorization and database transaction concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-08-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-08-13",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:59:30Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory and release evidence reviewed; no live testing or independent incident verification."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/Paymenter/Paymenter/security/advisories/GHSA-5gmm-hjfj-8ff7",
          "title": "Credit-refund double-spend race condition in service downgrade (doUpgrade)",
          "publisher": "Paymenter",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:59:30Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/Paymenter/Paymenter/releases/tag/v1.5.7",
          "title": "Paymenter v1.5.7 release",
          "publisher": "Paymenter",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:59:30Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Affected versions are listed as 1.5.6 and earlier. The reported scenario requires an authenticated customer and an active service eligible for downgrade.",
        "The maintainer reports excess spendable credit and potential operator loss, but supplies no production incident or independently measured loss. This review does not establish deployment exposure.",
        "The advisory header identifies CorwinDev as the publishing account, and Credits lists Pig-Tail as Reporter and CorwinDev as Remediation developer. The reviewed advisory provides no explicit article byline; these publication and credit roles do not establish article authorship. The advisory assigns CVE-2026-71537.",
        "The release page displays July 25 without a year in the reviewed rendering. No full patch-release date is asserted. Resource edition and version-release date remain null."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "portswigger-2025-upstream-http-framing-boundaries",
      "title": "Upstream HTTP framing and parser-consistency boundaries",
      "publisher": "PortSwigger",
      "authors": [
        "James Kettle"
      ],
      "primary_url": "https://portswigger.net/research/http1-must-die",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "integration-threat-modeling",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "version": null,
      "summary": "The researcher explains how inconsistent message-boundary interpretation across proxies and origins can break request isolation on shared upstream connections. Client-facing HTTP/2 alone does not remove this risk when intermediaries translate requests into HTTP/1.1.",
      "defensive_use": "Review framing contracts across every intermediary, including protocol translation and connection reuse. Consider upstream HTTP/2, consistent validation and normalization, and isolation tradeoffs where legacy transport remains. Assess remediation against the architecture rather than relying on a front-end protocol label or filtering claim.",
      "prerequisites": [
        "HTTP request and response semantics",
        "Reverse-proxy and origin-server architecture"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Primary article readable without login."
      },
      "dates": {
        "published": {
          "value": "2025-08-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Original article publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2025-10-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Displayed update date; not original publication."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:59:12Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed the primary article’s conceptual explanation and defensive sections. Historical research remains relevant to 2026 architecture reviews; vendor capabilities require separate current verification."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://portswigger.net/research/http1-must-die",
          "title": "HTTP/1.1 must die: the desync endgame",
          "publisher": "PortSwigger",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:59:12Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Protocol migration is the researcher’s recommendation, not proof that every HTTP/2 implementation is secure.",
        "Historical cases and vendor support observations do not establish current vulnerabilities or feature availability.",
        "Linked operational material is omitted. No individual award qualification or testing authorization is implied."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "portswigger-web-security-academy-controlled-training",
      "title": "Web Security Academy: Free Online Training from PortSwigger",
      "publisher": "PortSwigger",
      "authors": [],
      "primary_url": "https://portswigger.net/web-security",
      "resource_type_id": "training-lab",
      "topic_ids": [
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "concurrency-reasoning"
      ],
      "version": null,
      "summary": "Free web-security lessons and deliberately designed interactive training environments. Covers authentication, access control, business logic, API security, and other application-security fundamentals.",
      "defensive_use": "Learn concepts in the provider's controlled exercises, then use that understanding for secure-design and remediation work within an approved scope.",
      "prerequisites": [
        "Basic HTTP and browser concepts",
        "A free account for progress tracking",
        "Use only the supplied training environments for exercises"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T14:50:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Review records accessible official guidance as of this date; living content and current versions may change."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://portswigger.net/web-security",
          "title": "Web Security Academy: Free Online Training from PortSwigger",
          "publisher": "PortSwigger",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T14:50:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Some labs have additional software requirements; no software or tool recommendations are included here",
        "Training access is not authorization to test third-party systems"
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "postgresql-transaction-isolation-business-invariants",
      "title": "PostgreSQL 18: Transaction Isolation and Business Invariants",
      "publisher": "PostgreSQL Global Development Group",
      "authors": [],
      "primary_url": "https://www.postgresql.org/docs/18/applevel-consistency.html",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "approval-state-integrity"
      ],
      "version": "PostgreSQL 18 documentation, sections 13.4 and 13.5",
      "summary": "Explains why a stable database snapshot alone does not preserve business rules across concurrent transactions. PostgreSQL distinguishes serializable consistency from explicit locking and requires serialization-failure retries to repeat the whole transaction, including the decisions that produced its writes.",
      "defensive_use": "For an owned application, document the invariant, the transaction boundary and the isolation or locking assumptions that protect it. As an editorial application, connect approval-state decisions to their database consistency requirements; do not assume that repeating only the final write revalidates an earlier decision.",
      "prerequisites": [
        "Basic database transactions and isolation levels",
        "Application business rules and state transitions"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Both official documentation sections were publicly readable without sign-in."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed sections do not establish a page publication or edition-release date; site-wide news banners are not page dates."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed sections do not establish a page publication or edition-release date; site-wide news banners are not page dates."
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed sections do not establish a page publication or edition-release date; site-wide news banners are not page dates."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T18:52:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed both official PostgreSQL 18 sections. Version-scoped documentation is maintained; review time does not establish publication time or an immutable revision."
      },
      "sources": [
        {
          "id": "consistency",
          "url": "https://www.postgresql.org/docs/18/applevel-consistency.html",
          "title": "PostgreSQL 18: Data Consistency Checks at the Application Level",
          "publisher": "PostgreSQL Global Development Group",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T18:50:48Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "retry",
          "url": "https://www.postgresql.org/docs/18/mvcc-serialization-failure-handling.html",
          "title": "PostgreSQL 18: Serialization Failure Handling",
          "publisher": "PostgreSQL Global Development Group",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T18:50:48Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "PostgreSQL-specific semantics must not be assumed for another database or version. The documented serializable-integrity approach requires consistent participation by relevant reads and writes.",
        "The documented serializable protection does not extend to hot standby or logical replicas; deployment boundaries matter.",
        "Unique-key and exclusion-constraint errors can be persistent rather than transient; they do not justify blanket retries. Retrying does not guarantee eventual completion.",
        "This is conceptual defensive education, not a vulnerability finding, testing authorization or executable concurrency recipe."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "privacycg-storage-access-permission-activation-boundary",
      "title": "Storage Access API: permission, document activation and cookie eligibility",
      "publisher": "Privacy Community Group",
      "authors": [
        "Benjamin VanderSloot",
        "Johann Hofmann",
        "Anne van Kesteren"
      ],
      "primary_url": "https://privacycg.github.io/storage-access/",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "integration-threat-modeling"
      ],
      "version": "Draft Community Group Report, 22 May 2026",
      "summary": "The API draft distinguishes permission for the top-level and embedded site pair from activated access in a document and cookie eligibility on each request. Secure context, origin, embedding-policy and sandbox conditions still apply. Navigation and redirects constrain continuity; a document's access does not authorize arbitrary cross-origin cookie attachment. The companion Headers draft adds resource-controlled activation of an existing permission, independently of permission to read cross-origin responses.",
      "defensive_use": "Editorial guidance: model permission, document access and request eligibility separately. Review denial, revocation and navigation paths, minimize resource opt-in, and retain independent server authorization and CSRF defenses. Cookie availability does not establish authority for a business action.",
      "prerequisites": [
        "Same-site versus same-origin relationships, embedded documents and HTTP cookies"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Publicly readable drafts."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication date not established."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separately released edition established."
        },
        "source_displayed": {
          "value": "2026-05-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "api-draft",
          "note": "Displayed API draft date, not original publication or final-standard release."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T15:06:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed both evolving drafts and their relevant permission, request and security sections. No browser behavior testing."
      },
      "sources": [
        {
          "id": "api-draft",
          "url": "https://privacycg.github.io/storage-access/",
          "title": "The Storage Access API",
          "publisher": "Privacy Community Group",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T15:04:39Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "headers-draft",
          "url": "https://privacycg.github.io/storage-access-headers/",
          "title": "Storage Access Headers",
          "publisher": "Privacy Community Group",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T15:04:34Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Both publications are Draft Community Group Reports. The API draft is outside W3C's standards track and is not a WHATWG Living Standard. The technical-standard taxonomy includes drafts; listed authors are the API's current editors.",
        "The companion Headers draft displays 17 December 2025. Its opt-in uses an existing grant; it does not create initial permission. Cookie attachment and CORS response readability remain separate decisions.",
        "Document activation here means enabled storage access, distinct from a user gesture. A stored permission alone does not establish current document access; the API considers revocation and masks denied permission-query state.",
        "This record focuses on HTTP cookies. Non-cookie extensions, browser parity and deployed conformance are not established by this review."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "prowler-2026-saml-tenant-issuance-binding",
      "title": "Prowler SAML: retain validated tenant authority",
      "publisher": "Prowler",
      "authors": [],
      "primary_url": "https://github.com/prowler-cloud/prowler/security/advisories/GHSA-h8m9-jgf8-vwvp",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "security-token-design",
        "authorization-modeling"
      ],
      "version": null,
      "summary": "CVE-2026-59151 concerns token issuance selecting a tenant from an asserted email domain instead of retaining the validated SAML configuration. Maintainers describe potential cross-tenant account takeover. Their adapter-level linking-call demonstration does not establish persisted account linkage, complete token issuance or production compromise.",
      "defensive_use": "Keep federation configuration, accepted identity claims, membership changes and issued-token tenant consistent. The advisory lists Prowler API through 5.30.2 as affected and 5.30.3 as patched; no patch-release date is established here.",
      "prerequisites": [
        "Basic federation and object-level authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication, not software patch release."
        },
        "source_displayed": {
          "value": "2026-06-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication, not software patch release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:49:44Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory reviewed; no immutable educational edition established."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/prowler-cloud/prowler/security/advisories/GHSA-h8m9-jgf8-vwvp",
          "title": "SAML Domain Claiming Enables Cross-Tenant Account Takeover",
          "publisher": "Prowler",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:49:44Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires SAML, authenticated control of a tenant configuration and identity provider, and a target domain mapped to another SAML tenant; no victim interaction.",
        "Configured domains remain globally unique. The advisory narrative corrects conflicting older demonstration comments.",
        "Credits: EQSTLab, reporter; AdriiiPRodri, remediation developer; jfagoagas, coordinator/publishing account; josema-xyz, analyst. Article authorship is not established.",
        "Broader access and persistence are potential consequences. The fix was not independently audited.",
        "The displayed test mocks the linking method and checks its invocation with an existing user; it is narrower evidence than completed persistent linking."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "pterodactyl-2026-delegated-token-purpose-binding",
      "title": "Pterodactyl: delegated tokens must preserve action-specific authority",
      "publisher": "Pterodactyl",
      "authors": [
        "anthonyphysgun"
      ],
      "primary_url": "https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic",
        "identity"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification",
        "security-token-design",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "GHSA-8r6w-3qq5-4p4r describes an authorization mismatch between the Panel and Wings. Tokens established an authenticated user and server context without adequately separating operation purpose. The maintainer-published report describes an authenticated subuser gaining file-upload authority on an already accessible server despite lacking the required creation permission.",
      "defensive_use": "Editorial lesson: trusted issuer and valid signature establish token provenance, not authorization for every consumer. Require explicit purpose at issuance and matching operation scope at consumption. Panel 1.12.3 release notes require a scope when generating tokens; Wings 1.12.2 release notes describe verifying subsystem-required scopes. Review the producer and consumer together.",
      "prerequisites": [
        "Basic server-side authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-06-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-06-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T10:50:10Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and linked remediation evidence reviewed; deployment status was not assessed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r",
          "title": "Improper JWT scoping permits uploads without file-creation permission",
          "publisher": "Pterodactyl",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:50:10Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "panel-release",
          "url": "https://github.com/pterodactyl/panel/releases/tag/v1.12.3",
          "title": "Panel v1.12.3 release notes",
          "publisher": "Pterodactyl",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:50:10Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "wings-release",
          "url": "https://github.com/pterodactyl/wings/releases/tag/v1.12.2",
          "title": "Wings v1.12.2 release notes",
          "publisher": "Pterodactyl",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T10:50:10Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "Requires existing subuser access with a lower-privilege capability such as console connection or downloads. The advisory explicitly excludes users without subuser access to the server. Unauthorized upload is supported; cross-server takeover or command execution is not established here.",
        "CVE-2026-54593. The advisory lists Panel before 1.12.3 and Wings before 1.12.2 as affected, with those versions patched. Release notes support the stated remediation design; exact patch implementation and deployed coverage were not independently verified.",
        "Published June 6, 2026 by anthonyphysgun; TrixterTheTux is credited as reporter. Product version numbers are not educational-resource editions. No award evidence is claimed."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "pypdf-2026-attachment-processing-cost-boundary",
      "title": "pypdf: bound repeated work when reading embedded attachments",
      "publisher": "py-pdf / pypdf",
      "authors": [
        "stefan6419846"
      ],
      "primary_url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-102999 concerns excessive processing time in the dictionary-based embedded-file interface. The maintainer explains that retrieving each attachment repeatedly parsed the full attachment list. Thus input structure could multiply processing work even when each individual retrieval looked ordinary. The advisory identifies versions before 6.19.0 as affected.",
      "defensive_use": "The maintainer identifies 6.19.0 as patched. The merged correction records file objects by name so subsequent retrieval mostly accesses the corresponding stream directly. Editorial lesson for document-processing services: review aggregate complexity across convenience APIs, not only individual parsing calls, and maintain independent worker time and resource budgets.",
      "prerequisites": [
        "Document-processing pipelines and PDF embedded-file concepts",
        "Basic algorithmic complexity and resource isolation"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and remediation references readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-09-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established; software patch chronology is retained in the caveats."
        },
        "source_displayed": {
          "value": "2026-09-16",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed beside the advisory publisher."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:39:01Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed maintainer advisory, release and merged remediation discussion; no vulnerability reproduction or independent patch testing performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj",
          "title": "Possible long runtimes with large amount of embedded files",
          "publisher": "py-pdf / pypdf",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:39:01Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/py-pdf/pypdf/releases/tag/6.19.0",
          "title": "Version 6.19.0, 2026-09-16",
          "publisher": "py-pdf / pypdf",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:39:01Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "remediation",
          "url": "https://github.com/py-pdf/pypdf/pull/4081",
          "title": "Reduce number of full data lookups for attachment mapping API",
          "publisher": "py-pdf / pypdf",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:39:01Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The advisory requires use of the dictionary-based embedded-file API. Merely receiving a PDF or using unrelated pypdf functionality does not establish exposure.",
        "The public advisory confirms long-runtime impact but does not provide measured production outage evidence; no execution or confidentiality impact is established.",
        "jungmingi-lab is credited as reporter; stefan6419846 published the advisory and authored the remediation explanation.",
        "The correction merged September 14, 2026; release and advisory publication occurred September 16. The release classifies this change as a performance improvement, while the separate advisory identifies its security relevance.",
        "No bounty claim is made. Learning prerequisites and service-level budget recommendations are editorial.",
        "The cited software release is dated 2026-09-16; it is distinct from the advisory publication and is not a claim about the latest available release."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "python-subprocess-interpreter-boundaries",
      "title": "Python subprocess: executable, argument, and interpreter boundaries",
      "publisher": "Python Software Foundation",
      "authors": [],
      "primary_url": "https://docs.python.org/3.14/library/subprocess.html#security-considerations",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "interpreter-boundaries"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review"
      ],
      "version": "Python 3.14 documentation branch",
      "summary": "Runtime documentation distinguishes the selected executable, its arguments, and shell interpretation. Python does not implicitly select a shell, but Windows may launch batch files through one. The companion shlex reference limits its quoting guarantees to Unix shells; quoting is not a portable substitute for understanding the receiving interpreter.",
      "defensive_use": "Editorial learning objective: distinguish preserving argument boundaries from authorizing their meaning. Review which executable and interpreter receive data, what actions the receiving program assigns to arguments, and whether those actions fit the intended authority. This resource supports conceptual design review, without execution recipes.",
      "prerequisites": [
        "Basic familiarity with processes, arguments, and operating-system differences."
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public runtime documentation; no account was needed for the reviewed sections."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed sections do not establish this educational resource date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed sections do not establish this educational resource date."
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed sections do not establish this educational resource date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T23:22:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the versioned Python 3.14 subprocess security considerations and shlex.quote warning. Documentation can change; this is not an implementation or platform compatibility test."
      },
      "sources": [
        {
          "id": "python-subprocess-security",
          "url": "https://docs.python.org/3.14/library/subprocess.html#security-considerations",
          "title": "subprocess: Security Considerations",
          "publisher": "Python Software Foundation",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T23:22:00Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "python-shlex-quote",
          "url": "https://docs.python.org/3.14/library/shlex.html#shlex.quote",
          "title": "shlex.quote: Unix-shell portability warning",
          "publisher": "Python Software Foundation",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T23:22:00Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "Windows batch-file handling can involve shell parsing even when the application has not explicitly selected a shell. The runtime guidance for this case is conditional, not a universal recommendation to enable shell execution.",
        "shlex quoting is not guaranteed correct for non-POSIX shells or Windows shells.",
        "The authorization distinction is editorial synthesis, not a claim that these Python APIs enforce application policy.",
        "No vulnerability finding, award, payload, reproduction sequence, or testing authorization is established."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "qwik-2026-resumability-comment-serialization-boundary",
      "title": "Qwik: resumability metadata must preserve HTML serialization boundaries",
      "publisher": "QwikDev",
      "authors": [
        "Varixo"
      ],
      "primary_url": "https://github.com/QwikDev/qwik/security/advisories/GHSA-m6jq-g7gq-5w3c",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "browser-isolation-review"
      ],
      "version": null,
      "summary": "The maintainer describes unsafe serialization of virtual-component metadata into server-rendered HTML comments. Application-controlled attributes could cross from serialized state into browser interpretation when user influence reached their names or values. The reported impact is same-origin browser script execution, with possible resumability-state disruption. The advisory does not document a production compromise or independently measured downstream data loss.",
      "defensive_use": "The maintainer identifies 1.19.0 as patched. Editorial lesson: serialization safety depends on the actual browser context, including structural metadata and comment boundaries, rather than only visible text or conventional attributes. Review all server-to-client state representations and preserve the contract between their encoder and consumer. A patch for this mechanism is not proof that every application output path is safe.",
      "prerequisites": [
        "Server-rendered HTML and browser parsing contexts",
        "Framework resumability and serialized component metadata"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer security advisory."
      },
      "dates": {
        "published": {
          "value": "2026-02-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication, not software patch release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition release established."
        },
        "source_displayed": {
          "value": "2026-02-03",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:10:39Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary maintainer evidence reviewed. No exploit reproduction, live testing, or independent patch verification performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/QwikDev/qwik/security/advisories/GHSA-m6jq-g7gq-5w3c",
          "title": "Qwik SSR XSS via Unsafe Virtual Node Serialization",
          "publisher": "QwikDev",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:10:39Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "changelog",
          "url": "https://github.com/QwikDev/qwik/blob/main/packages/qwik/CHANGELOG.md",
          "title": "Qwik core changelog",
          "publisher": "QwikDev",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:10:39Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "CVE-2026-25148. Varixo published the advisory; wodzen is credited as reporter.",
        "The application prerequisite is user influence over dynamically populated virtual-node attribute names or values. The maintainer excludes hard-coded attributes.",
        "The package table names qwik, while the prose names qwik-city. Preserve this naming inconsistency rather than inferring package equivalence.",
        "Advisory publication is February 3, 2026. The exact software patch release date was not established and is not substituted into resource-edition chronology.",
        "The reviewed official core changelog contains a 1.19.0 section but does not independently explain this security fix. Remediation attribution rests on the maintainer advisory.",
        "No bounty is established. Learning prerequisites and generalized defensive guidance are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "react-router-2026-hydration-error-constructor-boundary",
      "title": "React Router: hydrated error metadata must not select client behavior",
      "publisher": "React Router / Remix",
      "authors": [
        "brophdawg11"
      ],
      "primary_url": "https://github.com/remix-run/react-router/security/advisories/GHSA-337j-9hxr-rhxg",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "error-response-design"
      ],
      "version": null,
      "summary": "The maintainer describes an SSR-to-hydration trust failure: application code that lets untrusted input alter aspects of caught server errors could cause unexpected client constructor execution and outbound network activity. The prerequisite is unusually specific application behavior. The case distinguishes transporting error data from granting that data authority over client reconstruction.",
      "defensive_use": "The advisory identifies 7.18.0 as patched. Editorial lesson: preserve a narrow, inert contract for errors crossing the server/client boundary, including metadata used to reconstruct them. Review error transport separately from visible error text, and constrain client interpretation to explicitly supported representations. The reviewed advisory does not establish the exact patch implementation.",
      "prerequisites": [
        "Server-side rendering and client hydration",
        "Error serialization and data-versus-behavior boundaries"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and release page."
      },
      "dates": {
        "published": {
          "value": "2026-07-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition established."
        },
        "source_displayed": {
          "value": "2026-07-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Explicit advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:19:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory and release page read. No live testing or independent patch execution."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/remix-run/react-router/security/advisories/GHSA-337j-9hxr-rhxg",
          "title": "Arbitrary client-side constructor injection via React Router SSR Hydration",
          "publisher": "React Router / Remix",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:18:30Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0",
          "title": "React Router v7.18.0 release",
          "publisher": "React Router / Remix",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:18:52Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "CVE-2026-53666. brophdawg11 published the advisory; yoyomiski is credited as reporter. The affected range is at least 6.4.0 and below 7.18.0.",
        "The maintainer limits applicability to Framework Mode and Data Mode with manual SSR/hydration, excluding Declarative Mode. Do not infer general client code execution, server compromise, or demonstrated data theft from the bounded description.",
        "The software release page displays June 16 without a year in retrieved text. A full patch-release date is not asserted or substituted for educational-resource chronology.",
        "No individual bounty is established. Learning prerequisites and generalized review guidance are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "rfc-10017-browser-oauth-token-custody",
      "title": "RFC 10017: OAuth 2.0 for Browser-Based Applications",
      "publisher": "Internet Engineering Task Force / RFC Editor",
      "authors": [
        "Aaron Parecki",
        "Philippe De Ryck",
        "David Waite"
      ],
      "primary_url": "https://www.rfc-editor.org/rfc/rfc10017.html",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "browser-isolation-review"
      ],
      "version": "RFC 10017 / BCP 212",
      "summary": "Compares browser-only OAuth clients, token-mediating backends, and backend-for-frontend architectures through their different token-custody and session boundaries. Separates protection of token material from the residual authority of compromised same-origin application code.",
      "defensive_use": "Document which component holds each credential, binds the user session, and enforces request destinations. Compare those responsibilities and residual risks against an owned application’s architecture.",
      "prerequisites": [
        "OAuth client and resource-server roles",
        "Browser origins, cookies, and HTTP redirects"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official specification readable without an account at review time."
      },
      "dates": {
        "published": {
          "value": "2026-08",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publication date of this RFC or final specification."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:40:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed this identified edition and its relevant design and security sections. Retrieval date is separate from publication; later revisions or errata may exist."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.rfc-editor.org/rfc/rfc10017.html",
          "title": "RFC 10017: OAuth 2.0 for Browser-Based Applications",
          "publisher": "Internet Engineering Task Force / RFC Editor",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:40:00Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Backend token custody does not make compromised application code harmless.",
        "Browser-specific guidance complements RFC 9700; it does not establish security of a particular deployment."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "rfc-9700-oauth-security-best-current-practice",
      "title": "RFC 9700: Best Current Practice for OAuth 2.0 Security",
      "publisher": "Internet Engineering Task Force / RFC Editor",
      "authors": [],
      "primary_url": "https://www.rfc-editor.org/rfc/rfc9700.html",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "identity"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "authorization-modeling",
        "integration-threat-modeling"
      ],
      "version": "RFC 9700 / BCP 240",
      "summary": "Consensus guidance updating OAuth's security model with deployment experience, stronger protocol requirements, and deprecated insecure patterns. A primary reference for identity integration reviews.",
      "defensive_use": "Compare an owned integration's documented design against the standard and record deviations and compensating controls.",
      "prerequisites": [
        "OAuth roles and authorization flows",
        "HTTP redirects and TLS",
        "Basic token and session concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Verified as free at review time; optional accounts or provider features may have separate terms."
      },
      "dates": {
        "published": {
          "value": "2025-01",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T14:50:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Review records accessible official guidance as of this date; living content and current versions may change."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.rfc-editor.org/rfc/rfc9700.html",
          "title": "RFC 9700: Best Current Practice for OAuth 2.0 Security",
          "publisher": "Internet Engineering Task Force / RFC Editor",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T14:50:00Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "rocketchat-2026-asynchronous-identity-verification",
      "title": "Rocket.Chat: authentication must await a completed verification decision",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Peter Stöckli"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2026-004_GHSL-2026-005_Rocket_Chat/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "identity",
        "web-foundations"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "concurrency-reasoning",
        "patch-verification"
      ],
      "version": null,
      "prerequisites": [
        "Basic server-side authentication and authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-03-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Resource has no stated release version; software fixes are described separately."
        },
        "source_displayed": {
          "value": "2026-03-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T09:29:37Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Research and maintainer evidence reviewed; no live deployment or remediation testing performed."
      },
      "content_scope": "defensive_education",
      "summary": "CVE-2026-28514 concerned asynchronous password verification in the enterprise account service. The authentication decision treated an unfinished validation object as success instead of using its eventual result. The researcher tested Rocket.Chat 7.13.2; the maintainer corroborates unauthorized access to available service methods, with possible account takeover depending on subsequent application behavior.",
      "defensive_use": "Editorial lesson: model authentication as a completed, explicit decision; pending, rejected, and failed validation must not imply success. Maintain regression coverage for asynchronous rejection and service-specific authentication equivalence. The maintainer remediation requires waiting for verification and recommends tooling to detect unhandled asynchronous results.",
      "caveats": [
        "Requires the affected enterprise streaming/account-service deployment and an account with password authentication configured; the reported identity must be known or guessable. Do not generalize this to every Rocket.Chat installation or authentication mode.",
        "The researcher describes broad takeover potential. The maintainer impact statement is narrower: access to available service methods, with takeover dependent on the application path. Neither source supplies a customer incident count.",
        "Reported January 9, 2026; the researcher dates the initial 8.0.0 fix to January 12 and supported-version fixes to March 5. The maintainer advisory was published March 5; detailed research March 12. These are not resource version-release dates.",
        "Maintainer-listed patched releases: 8.0.0, 7.13.3, 7.12.4, 7.11.4, 7.10.7, 7.9.8 and 7.8.6. No deployment remediation was verified.",
        "The research page also covers CVE-2026-30833; this resource is confined to asynchronous authentication verification and does not summarize a combined attack.",
        "Byline: Peter Stöckli. Discovery used GitHub Security Lab Taskflow Agent, manually verified by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial."
      ],
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2026-004_GHSL-2026-005_Rocket_Chat/",
          "title": "GHSL-2026-004_GHSL-2026-005: Authentication bypass in Rocket.Chat",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:29:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-advisory",
          "url": "https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-w6vw-mrgv-69vf",
          "title": "Users can login with any password via the EE ddp-streamer-service",
          "publisher": "Rocket.Chat",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:29:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "samlify-2026-assertion-generation-claim-integrity",
      "title": "samlify: signing does not establish claim provenance",
      "publisher": "samlify",
      "authors": [
        "tngan"
      ],
      "primary_url": "https://github.com/tngan/samlify/security/advisories/GHSA-34r5-q4jw-r36m",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "The maintainer describes inconsistent escaping between XML attribute and element-text contexts during SAML assertion generation. User-controlled profile values could change assertion structure before the identity provider signed it. The service provider subsequently accepted extra attributes as authenticated claims; privilege escalation depends on using those attributes for authorization.",
      "defensive_use": "Editorial reasoning: signatures protect the generated representation, not the authority of each input used to construct it. Keep profile text separate from authorization-claim structure, use context-correct serialization before signing, and review which upstream actors may supply claims consumed as roles. A signature check alone cannot repair a compromised issuance boundary.",
      "prerequisites": [
        "SAML issuer/relying-party roles, XML contexts and claim-based authorization"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer disclosure."
      },
      "dates": {
        "published": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "source_displayed": {
          "value": "2026-05-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T16:19:37Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary source reviewed; no independent reproduction or deployment assessment."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/tngan/samlify/security/advisories/GHSA-34r5-q4jw-r36m",
          "title": "SAML attribute-generation integrity advisory",
          "publisher": "samlify",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T16:19:37Z",
          "supports": [
            "summary",
            "dates",
            "version"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/tngan/samlify/releases/tag/v2.13.0",
          "title": "Release v2.13.0",
          "publisher": "samlify",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T16:19:37Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "The advisory identifies master/v2.10.2 as affected and 2.13.0 as patched; it does not establish a complete affected-version interval. Exposure requires user-controlled values reaching assertion generation and a relying party trusting the resulting attributes.",
        "The published example supports added attributes being parsed; downstream privileged application actions are conditional consequences, not evidence of a breached deployment.",
        "tngan published the advisory; RootUp is credited as reporter in both advisory and release notes. The 2.13.0 release explicitly references this advisory. Its displayed May 14 timestamp omits the year in retrieved text, so no full patch date is asserted. Resource edition remains null."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "sentry-2026-organization-object-authorization",
      "title": "Sentry: resource ownership must match the authorized organization",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Peter Stöckli"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2025-130_Sentry/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "identity"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "prerequisites": [
        "Basic server-side authentication and authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-02-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Resource has no stated release version; software fixes are described separately."
        },
        "source_displayed": {
          "value": "2026-02-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T09:29:37Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Research and maintainer evidence reviewed; no live deployment or remediation testing performed."
      },
      "content_scope": "defensive_education",
      "summary": "CVE-2026-26004 concerned a missing organization constraint in event retrieval. A permission check on the active organization did not establish ownership of the requested object. GitHub Security Lab reports cross-organization event disclosure in tested Sentry 25.12.0.",
      "defensive_use": "Editorial lesson: carry tenant identity into resource resolution, rather than checking actor permissions and object lookup independently. The maintainer patch adds the organization constraint and regression coverage for cross-organization denial. Review equivalent response paths against the same invariant.",
      "caveats": [
        "The reported case requires an authenticated user with event-read permission in their own organization. It establishes unauthorized reading, not modification or account takeover; no customer incident or measured data-loss total is supplied.",
        "Research was reported December 23, 2025. Maintainer pull request 105601 was merged January 2, 2026. Reviewed sources do not establish a packaged fixed release or production rollout date; merge is not deployment.",
        "The researcher says Sentry fixed the issue but declined to issue a CVE; GitHub assigned it February 10. Preserve this provenance rather than implying vendor-issued CVE publication.",
        "Byline: Peter Stöckli. Discovery is credited to a GitHub Security Lab AI agent, reviewed by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial."
      ],
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2025-130_Sentry/",
          "title": "GHSL-2025-130: Unauthorized access to event data across organizational boundaries in Sentry - CVE-2026-26004",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:29:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-patch",
          "url": "https://github.com/getsentry/sentry/commit/45bc78fd57514a04eb62e73dd1eeb3ca2d723997",
          "title": "Add functional org filter to GroupEventJsonView (#105601)",
          "publisher": "Sentry",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:29:37Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "maintainer-merge",
          "url": "https://github.com/getsentry/sentry/pull/105601",
          "title": "Add functional org filter to GroupEventJsonView",
          "publisher": "Sentry",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T09:29:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "serialize-javascript-2026-output-code-boundary",
      "title": "Serialize JavaScript: every serialized field must retain data semantics",
      "publisher": "Yahoo serialize-javascript",
      "authors": [
        "redonkulus"
      ],
      "primary_url": "https://github.com/yahoo/serialize-javascript/security/advisories/GHSA-5c6j-r48x-rmvq",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification",
        "interpreter-boundaries"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "version": null,
      "summary": "The maintainer describes inconsistent escaping across structured-object serialization: some object-derived strings entered generated JavaScript without equivalent protection. Code execution requires attacker-influenced objects and subsequent executable interpretation of the output. The advisory demonstrates local execution; universal remote exploitability or production compromise is not established.",
      "defensive_use": "The maintainer advisory and official release identify 7.0.3 as the repair. Editorial lesson: audit serialization contracts across every supported type and output consumer, including overridable object behavior. Prefer data-only exchange where possible and avoid granting generated text execution authority merely because a serializer produced it.",
      "prerequisites": [
        "JavaScript object behavior and serialization contracts",
        "Data versus executable-output trust boundaries"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-02-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication, not software-release chronology."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established."
        },
        "source_displayed": {
          "value": "2026-02-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Advisory publication date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T08:19:27Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and official release reviewed. No reproduction or independent patch testing performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/yahoo/serialize-javascript/security/advisories/GHSA-5c6j-r48x-rmvq",
          "title": "RCE via RegExp.flags and Date.prototype.toISOString()",
          "publisher": "Yahoo serialize-javascript",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:19:27Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/yahoo/serialize-javascript/releases/tag/v7.0.3",
          "title": "Serialize JavaScript v7.0.3 release",
          "publisher": "Yahoo serialize-javascript",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:19:27Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "reviewed-entry",
          "url": "https://github.com/advisories/GHSA-5c6j-r48x-rmvq",
          "title": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
          "publisher": "GitHub Advisory Database",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T08:19:27Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "The maintainer table says affected versions are below 7.0.2, but its prose includes 7.0.2. The GitHub-reviewed entry includes 7.0.2; all reviewed sources identify 7.0.3 as patched.",
        "The maintainer labels this an incomplete CVE-2020-7660 fix, while the GitHub-reviewed entry assigns no known CVE. The stable identity here is GHSA-5c6j-r48x-rmvq; its 2026 publication does not make the earlier CVE a 2026 identifier.",
        "The advisory credits uug4na as reporter; redonkulus is the publishing maintainer. No bounty established.",
        "The software-release page displays February 27 without a year in the retrieved rendering. No exact software-release date is inferred; advisory publication is independently explicit.",
        "Learning prerequisites and generalized design guidance are editorial. Control of ordinary JSON alone does not establish the object-control and executable-consumer prerequisites."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "slsa-v1-2-supply-chain-build-provenance",
      "title": "SLSA v1.2: supply-chain security and build provenance",
      "publisher": "SLSA Community",
      "authors": [],
      "primary_url": "https://slsa.dev/spec/v1.2/",
      "resource_type_id": "security-standard",
      "topic_ids": [
        "supply-chain",
        "verification"
      ],
      "skillset_ids": [
        "pipeline-trust-modeling",
        "cache-artifact-isolation",
        "dependency-provenance",
        "defensive-evidence-writing"
      ],
      "version": "1.2",
      "summary": "Learn to assess software supply-chain assurance using distinct source and build tracks. The build track progresses from recording provenance to authenticated hosted builds and stronger platform isolation. Build provenance connects an artifact to its builder, inputs, and build definition so consumers can evaluate whether its production matches expectations.",
      "defensive_use": "Map documented build controls and provenance expectations to an approved architecture review; distinguish attestation presence from trusted verification.",
      "prerequisites": [
        "Basic familiarity with version control and continuous integration",
        "Understanding of software artifacts, hashes, and digital-signature concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official documentation was publicly readable at review time; implementation services can have separate costs."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": "2025-11-24",
          "precision": "day",
          "basis": "explicit",
          "source_id": "release",
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T15:32:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Version-specific approved specification; stable entry point currently redirects to v1.2. Working Draft is separately labeled and was not treated as a stable release."
      },
      "sources": [
        {
          "id": "stable-entry",
          "url": "https://slsa.dev/spec/",
          "title": "Official stable entry point redirects to v1.2",
          "publisher": "SLSA Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T15:32:00Z",
          "supports": [
            "version"
          ]
        },
        {
          "id": "primary",
          "url": "https://slsa.dev/spec/v1.2/",
          "title": "Version 1.2 and Approved status",
          "publisher": "SLSA Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T15:32:00Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "release",
          "url": "https://slsa.dev/blog/2025/11/announce-slsa-v1.2",
          "title": "SLSA Community release announcement dated 24 November 2025",
          "publisher": "SLSA Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T15:32:00Z",
          "supports": [
            "dates",
            "version"
          ]
        },
        {
          "id": "build-levels",
          "url": "https://slsa.dev/spec/v1.2/build-track-basics",
          "title": "Build-level distinctions and provenance limitations",
          "publisher": "SLSA Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T15:32:00Z",
          "supports": [
            "summary",
            "version"
          ]
        },
        {
          "id": "build-provenance",
          "url": "https://slsa.dev/spec/v1.2/build-provenance",
          "title": "Build provenance model and predicate-version convention",
          "publisher": "SLSA Community",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T15:32:00Z",
          "supports": [
            "summary",
            "version"
          ]
        }
      ],
      "caveats": [
        "Build L1 provenance alone does not provide tamper protection.",
        "The specification version is 1.2, while the build-provenance predicate identifier remains https://slsa.dev/provenance/v1; the page explains this major-version convention.",
        "A recorded attestation is useful only within an explicit trust and verification model."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "spree-2026-guest-cart-association-authority",
      "title": "Spree: cart association must retain guest-possession checks",
      "publisher": "Spree",
      "authors": [
        "damianlegawiec"
      ],
      "primary_url": "https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-94462 concerns a guest-cart ownership transition that required a signed-in customer but omitted the cart-possession check enforced by sibling operations. Account authentication and object lookup were treated as sufficient authority to claim an unowned cart, exposing existing checkout addresses and changing ownership.",
      "defensive_use": "Editorial lesson: joining guest state to an account is a privileged ownership transition. Verify existing possession before mutation and response serialization; client-supplied proof helps only when the server checks it. The maintainer recommends backend releases 5.4.4 or 5.5.4 and says its storefront already supplied the required cart token.",
      "prerequisites": [
        "Basic object-level authorization and policy-composition concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary advisory readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-07-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed by the primary maintainer advisory."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-07-20",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed by the primary maintainer advisory."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:19:23Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary maintainer advisory reviewed. No live testing, independent reproduction or deployment verification performed."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2",
          "title": "Spree guest-cart association access-control advisory (GHSA-4825-p4xm-pcf2)",
          "publisher": "Spree",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:19:23Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires an authenticated store account, guest checkout enabled and an unassociated cart; address disclosure additionally requires stored checkout addresses. The advisory reports limited, recoverable cart reassignment and email changes, not anonymous access or account takeover.",
        "The primary advisory supplies technical impact analysis; no production incident or independently reproduced outcome is established.",
        "Published July 20, 2026 by damianlegawiec; reporter laijunyue is credited. The affected-version shorthand starts at 5.4.0 without an upper bound; use the stated patched branches rather than extrapolating. Software patch dates are unestablished and are not resource-edition dates."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "spree-2026-guest-order-authorization-proof",
      "title": "Spree: guest ownership still requires an authorization proof",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Peter Stöckli"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2026-029_Spree/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-25757 concerns completed guest orders. The access decision treated absence of an account owner as sufficient permission, while lookup did not require the separate order token. GHSL identifies the flaw in tested version 5.2.6; the maintainer corroborates guest-order disclosure.",
      "defensive_use": "Editorial lesson: a guest object needs an explicit authorization model even when no account owns it. Keep object identification separate from evidence of permission. The maintainer lists patched releases 5.0.8, 5.1.10, 5.2.7 and 5.3.2; this record does not independently verify their implementation.",
      "prerequisites": [
        "Basic object-level access-control concepts",
        "Familiarity with web request and response processing"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-03-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-03-12",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:30:37Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Research and maintainer advisory reviewed; no deployment or independent reproduction was assessed."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2026-029_Spree/",
          "title": "GHSL-2026-029: Insecure Direct Object Reference (IDOR) in Spree - CVE-2026-25757",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:30:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-advisory",
          "url": "https://github.com/spree/spree/security/advisories/GHSA-p6pv-q7rc-g4h9",
          "title": "Unauthenticated users can view completed guest orders by Order ID",
          "publisher": "Spree",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:30:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Exposure requires an affected storefront and a completed guest order identifier. Neither a signed-in account nor victim interaction is required; account-owned orders are not established as affected.",
        "The maintainer describes a controlled demonstration exposing guest-order details. GHSL identifies potential disclosure of names, addresses and phone numbers. No customer incident, measured data loss, write access or account takeover is established.",
        "GHSL records reporting on January 26, 2026 and publication of fixes and the maintainer advisory on February 5. The detailed research was published March 12. Resource edition release remains unknown and is separate from product patch chronology.",
        "The maintainer affected-version shorthand is ambiguous; do not interpret it as normalized branch ranges. Patched versions are reproduced as listed.",
        "The research byline is Peter Stöckli. Discovery is credited to GitHub Security Lab Taskflow Agent, with manual verification by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "steeltoe-2026-diagnostic-uri-data-minimization",
      "title": "Steeltoe: diagnostic URI masking must cover the complete data contract",
      "publisher": "Steeltoe",
      "authors": [
        "TimHess"
      ],
      "primary_url": "https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-8phw-xrj9-cpqp",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "secrets-containment",
        "secure-parser-review",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-75523 describes diagnostic URI masking that removed inline credentials but preserved query contents. The failed assumption was that sanitizing one URI component made the whole representation safe for secondary consumers. Request secrets could consequently cross into diagnostic responses and DEBUG logs.",
      "defensive_use": "Editorial lesson: define an explicit retention contract for each diagnostic field, then minimize before storage and fan-out. Check response and logging consumers separately. The advisory identifies 4.3.0 as patched; temporary mitigations include omitting query strings and disabling or authenticating diagnostic exposure.",
      "prerequisites": [
        "HTTP credentials, integration boundaries and secure data handling"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory."
      },
      "dates": {
        "published": {
          "value": "2026-09-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer publication date; distinct from database ingestion or patch release."
        },
        "source_displayed": {
          "value": "2026-09-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer publication date; distinct from database ingestion or patch release."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational edition established."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T14:19:06Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory reviewed; no software executed or deployment tested."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-8phw-xrj9-cpqp",
          "title": "Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets",
          "publisher": "Steeltoe",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T14:19:06Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Affected versions are <=4.2.0. The diagnostic endpoint requires explicit exposure and is not enabled by default; relevant traffic must carry query-string secrets. Log disclosure additionally requires the relevant DEBUG logging.",
        "The source describes disclosure to diagnostic readers, not demonstrated production compromise or universal account takeover. It does not detail the patch implementation or release date.",
        "The advisory credits manus-use as reporter."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "stripe-webhook-delivery-state-integrity",
      "title": "Stripe webhooks: authentic delivery and business-state integrity",
      "publisher": "Stripe",
      "authors": [],
      "primary_url": "https://docs.stripe.com/webhooks",
      "resource_type_id": "implementation-guide",
      "topic_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "Stripe documents duplicate deliveries, unordered events and renewed signatures and timestamps on retries. Signature verification establishes delivery authenticity; it does not establish that the business effect is new or that the event represents the latest application state.",
      "defensive_use": "Editorial lesson: model delivery acceptance, event identity and committed business effects as separate invariants. Review how application state stays consistent across repeated, delayed and concurrent work. A recent authenticated delivery can still describe an already-handled event.",
      "prerequisites": [
        "Basic HTTP webhook and asynchronous processing concepts",
        "Basic application state-transition and concurrency concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public documentation; service use is separate from reading access."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T19:41:18Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Official delivery-behavior, duplicate-event and replay-protection sections reviewed. No publication date or document edition was established; example API versions are not document dates."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://docs.stripe.com/webhooks",
          "title": "Receive Stripe events in your webhook endpoint",
          "publisher": "Stripe",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T19:41:18Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Provider-specific guidance, not a universal webhook contract, vulnerability disclosure or exactly-once guarantee. Delivery success does not prove completion of downstream business work.",
        "Stripe distinguishes repeated delivery of one event from separate Event objects representing duplicates. Identity rules must follow the relevant event semantics; timestamps alone do not establish order or uniqueness.",
        "The signed timestamp concerns a delivery attempt, not the age or ordering of the underlying business event. Provider retries receive new signatures and timestamps.",
        "Conceptual defensive education only. No incident, customer loss, patch effectiveness or third-party testing authorization is established."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "svelte-2026-hydration-output-context-boundary",
      "title": "Svelte hydration: serialization must preserve the enclosing output context",
      "publisher": "Camilo Vera",
      "authors": [
        "Camilo Vera"
      ],
      "primary_url": "https://caverav.cl/posts/svelte-hydratable-xss/svelte-hydratable-xss/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "web-foundations"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "version": null,
      "summary": "Research on CVE-2025-15265 explains a data-to-code boundary failure: hydration keys received JavaScript-string serialization without the HTML-context protection already used for values. The researcher demonstrates browser script execution in a minimal application. Account compromise is an application-dependent consequence, not evidence of a compromised production account.",
      "defensive_use": "Compare all fields crossing rendering contexts, including metadata keys. The researcher describes replacement with an HTML-safe serializer and regression coverage. The maintainer identifies Svelte 5.46.4 as patched. Preserve one encoding contract across keys and values, rather than treating valid JSON as sufficient for every output context.",
      "prerequisites": [
        "Server-side rendering and framework integration concepts",
        "Basic trust-boundary and secure-input review"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public researcher article and maintainer advisory readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-03-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": "Article displays this publication date; advisory disclosure is a separate event."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-03-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": "Article displays this publication date; advisory disclosure is a separate event."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T05:49:32Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Researcher article and maintainer advisory reviewed; no immutable article revision established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://caverav.cl/posts/svelte-hydratable-xss/svelte-hydratable-xss/",
          "title": "CVE-2025-15265: Svelte Hydratable Key SSR XSS - Lydian",
          "publisher": "Camilo Vera",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:49:32Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer",
          "url": "https://github.com/sveltejs/svelte/security/advisories/GHSA-6738-r8g5-qwp3",
          "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in svelte",
          "publisher": "Svelte",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:49:32Z",
          "supports": [
            "summary"
          ]
        },
        {
          "id": "research-advisory",
          "url": "https://fluidattacks.com/advisories/lydian",
          "title": "Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)",
          "publisher": "Fluid Attacks",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:49:32Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Affected behavior requires experimental async rendering and hydration keys influenced by untrusted input; ordinary Svelte use alone does not establish exposure.",
        "The advisory version table lists 5.46.0 through 5.46.3, while its summary says 5.46.0-2; the researcher and Fluid Attacks advisory support the broader table range.",
        "March 17 is the article publication; the researcher dates the separate fix and disclosure to January 15, 2026. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "sveltekit-2026-origin-routing-trust-boundary",
      "title": "SvelteKit: origin construction and routing must preserve server request authority",
      "publisher": "zhero_web_security",
      "authors": [
        "Rachid Allam",
        "Allam Yasser"
      ],
      "primary_url": "https://zhero-web-sec.github.io/research-and-things/avoiding-the-paradox-a-native-full-read-ssrf-and-oneshot-dos-in-sveltekit",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "web-foundations"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "untrusted-input-handling",
        "error-response-design",
        "patch-verification"
      ],
      "version": null,
      "summary": "Research on CVE-2025-67647 describes framework-internal routing consuming an origin derived from insufficiently trusted request metadata. The researcher demonstrates server-side response retrieval and process termination from unhandled network errors. The maintainer limits internal-service exposure to services reachable without authentication from the runtime; downstream cache effects depend on deployment behavior.",
      "defensive_use": "Trace which component authoritatively establishes the application origin, and contain failures in internal network operations. The maintainer lists SvelteKit 2.49.5 and adapter-node 5.5.1 as patched. Fixed-origin configuration and reverse-proxy host validation address origin trust, but do not substitute for patching the broader availability issue.",
      "prerequisites": [
        "Server-side rendering and framework integration concepts",
        "Basic trust-boundary and secure-input review"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public researcher article and maintainer advisory readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-01",
          "precision": "month",
          "basis": "explicit",
          "source_id": "research",
          "note": "Article displays this publication date; advisory disclosure is a separate event."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-01",
          "precision": "month",
          "basis": "explicit",
          "source_id": "research",
          "note": "Article displays this publication date; advisory disclosure is a separate event."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T05:49:32Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Researcher article and maintainer advisory reviewed; no immutable article revision established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://zhero-web-sec.github.io/research-and-things/avoiding-the-paradox-a-native-full-read-ssrf-and-oneshot-dos-in-sveltekit",
          "title": "Avoiding the paradox: A native full-read SSRF and one-shot DoS in SvelteKit",
          "publisher": "zhero_web_security",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:49:32Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer",
          "url": "https://github.com/sveltejs/kit/security/advisories/GHSA-j62c-4x62-9r35",
          "title": "Denial of service and possible SSRF when using prerendering",
          "publisher": "Svelte",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:49:32Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "The maintainer requires a prerendered route. SSRF additionally requires adapter-node without a configured origin and without reverse-proxy host validation. The advisory distinguishes the broader DoS case starting at SvelteKit 2.44.0 from the origin-dependent case starting at 2.19.0.",
        "The article provides demonstrations, not evidence of an actual third-party production compromise. Cache-related browser impact is conditional, not universal.",
        "The article displays January 2026 without a day; January 15 is its separately stated patch/advisory date. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "sylius-2026-component-argument-object-authorization",
      "title": "Sylius: component integrity does not authorize referenced objects",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Man Yue Mo"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2026-055_Sylius/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-31820 concerns client-supplied component action arguments used to load objects without ownership checks. Property checksums did not cover those arguments. GHSL describes cross-customer address disclosure in tested version 2.2.3-dev; the maintainer additionally identifies disclosure of cart and order financial summaries.",
      "defensive_use": "Editorial lesson: integrity protection on component state does not establish authority over every referenced object. Bind each lookup to the current customer or authorized session context. The maintainer lists fixes in 2.0.16, 2.1.12 and 2.2.3 and supplies a project-level authorization workaround; its correctness for customized deployments is not established here.",
      "prerequisites": [
        "Basic object-level access-control concepts",
        "Familiarity with web request and response processing"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary sources readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-03-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-03-17",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T11:30:37Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Research and maintainer advisory reviewed; no deployment or independent reproduction was assessed."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2026-055_Sylius/",
          "title": "GHSL-2026-055: Unauthorized access to PII in Sylius - CVE-2026-31820",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:30:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-advisory",
          "url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-2xc6-348p-c2x6",
          "title": "IDOR in Cart and Checkout LiveComponents",
          "publisher": "Sylius",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T11:30:37Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires an authenticated customer using affected shop components. The demonstrated research case concerns another customer’s address; the maintainer’s broader scope also covers order summaries because active carts and completed orders share a data model.",
        "The research describes controlled cross-customer disclosure, not an observed customer breach. The reviewed evidence does not establish write access, payment execution or account takeover.",
        "GHSL records reporting on February 19, 2026 and maintainer-advisory publication on March 9; detailed research was published March 17. Exact product release dates are not established by these sources. Resource edition release remains unknown.",
        "The development snapshot tested by GHSL is distinct from the final 2.2.3 release named as patched by the maintainer. No contradiction or remediation failure is inferred from the similar labels.",
        "The byline is Man Yue Mo. Discovery is credited to GitHub Security Lab Taskflow Agent, with manual verification by Peter Stöckli and Man Yue Mo; the maintainer credits both and the GHSL team. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "sylius-2026-payment-action-authority",
      "title": "Sylius: order ownership does not confer payment-operation authority",
      "publisher": "Sylius",
      "authors": [
        "TheMilek"
      ],
      "primary_url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-2rv4-pjmm-7fxf",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "business-logic",
        "authorization"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "approval-state-integrity",
        "integration-threat-modeling"
      ],
      "version": null,
      "summary": "The advisory distinguishes ownership of an order from authority over its payment operations. Customer-context requests were constrained by ownership but not by operation. A connected payment provider could therefore change financial state while local order status still indicated payment completion.",
      "defensive_use": "Editorial lesson: define operation permissions independently from object ownership, and reconcile provider outcomes with local fulfillment state. The advisory recommends rejecting disallowed customer-context operations before effects. Maintainer release notes corroborate remediation in 2.1.16 and 2.2.9.",
      "prerequisites": [
        "Basic application state machines, authorization and database transaction concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-09-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-09-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:59:30Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory and release evidence reviewed; no live testing or independent incident verification."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-2rv4-pjmm-7fxf",
          "title": "Shop API accepts arbitrary PaymentRequest actions, allowing a customer-triggered refund",
          "publisher": "Sylius",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:59:30Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release-21",
          "url": "https://github.com/Sylius/Sylius/releases/tag/v2.1.16",
          "title": "Sylius v2.1.16 security release",
          "publisher": "Sylius",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:59:30Z",
          "supports": [
            "version",
            "dates"
          ]
        },
        {
          "id": "release-22",
          "url": "https://github.com/Sylius/Sylius/releases/tag/v2.2.9",
          "title": "Sylius v2.2.9 security release",
          "publisher": "Sylius",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:59:30Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Affected ranges are listed as 2.0.0 through versions before 2.1.16, and 2.2.0 through versions before 2.2.9.",
        "Impact is conditional on an enabled production API and a gateway exposing the relevant financial operations. The advisory explicitly excludes a plain default installation lacking that gateway.",
        "The maintainer describes financial-state inconsistency and consequent merchant-loss risk, not a documented production loss. This review does not independently verify those outcomes.",
        "TheMilek published the advisory; acirtautas is credited as finder. The reviewed advisory displays no known CVE; no identifier is inferred from secondary indexing.",
        "Both release pages display September 2 without a year in the reviewed rendering. Full patch dates are not asserted; the educational resource edition remains unknown."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "sylius-2026-promotion-limit-atomicity",
      "title": "Sylius: promotion entitlement must be checked and consumed atomically",
      "publisher": "Sylius",
      "authors": [
        "NoResponseMate"
      ],
      "primary_url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-7mp4-25j8-hp5q",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "business-logic"
      ],
      "skillset_ids": [
        "concurrency-reasoning",
        "approval-state-integrity",
        "patch-verification"
      ],
      "version": null,
      "summary": "Promotion eligibility used stale in-memory counts, while consumption was persisted later without synchronization. Absolute counter writes could also lose concurrent updates. The failed boundary was between a provisional eligibility decision and committed entitlement across global promotion, coupon and per-customer limits.",
      "defensive_use": "Editorial lesson: model the limit check and entitlement consumption as one serialized decision. Accounting correctness alone does not prove eligibility correctness. In owned local models, verify that committed usage never exceeds the authorized allowance, including cancellation semantics.",
      "prerequisites": [
        "Basic authorization, application state machines and database transaction concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer evidence."
      },
      "dates": {
        "published": {
          "value": "2026-03-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-03-09",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:59:29Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Public primary evidence reviewed; no live testing or independent deployment verification."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-7mp4-25j8-hp5q",
          "title": "Promotion Usage Limit Bypass via Race Condition",
          "publisher": "Sylius",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:59:29Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The maintainer reports limit overruns without required authentication; a limited promotion or coupon and overlapping order processing are prerequisites. Financial loss is a potential consequence, not a measured production incident.",
        "The advisory lists fixes in 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12 and 2.2.3. Consult its branch-specific affected ranges. Patch dates are not asserted; resource edition remains null.",
        "NoResponseMate published the advisory. Reporters are Djibril Mounkoro (whiteov3rflow) and Bartłomiej Nowiński (bnBart); CVE-2026-31824."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "tanstack-2026-server-function-response-authority",
      "title": "TanStack Start: preserve server-owned response authority through errors",
      "publisher": "TanStack",
      "authors": [],
      "primary_url": "https://github.com/TanStack/router/security/advisories/GHSA-qx66-fv34-fjm8",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "interpreter-boundaries"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "error-response-design",
        "patch-verification"
      ],
      "version": null,
      "summary": "TanStack's CVE-2026-102989 advisory describes client request data entering internal middleware state. Failure handling could retain an untrusted result that response processing then accepted as an HTTP response. The maintainer confirms reflected same-origin XSS and classifies it as CWE-79. The boundary failure is client data acquiring server response authority, including on an error path.",
      "defensive_use": "The announced fix narrows accepted client input and checks server responses. Update dependencies and the lockfile, verify resolved @tanstack/start-server-core is at least 1.169.39, then rebuild and redeploy; local upgrades alone leave deployed code unchanged. Editorial lesson: keep internal state separate from public input, and preserve response provenance through exceptions. Supplementary edge controls do not replace the package fix.",
      "prerequisites": [
        "HTTP response handling, browser same-origin authority and reflected XSS concepts",
        "Middleware error handling and dependency-resolution basics"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and supporting security announcement."
      },
      "dates": {
        "published": {
          "value": "2026-09-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "GitHub explicitly labels this as the advisory publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition date is established."
        },
        "source_displayed": {
          "value": "2026-09-30",
          "precision": "day",
          "basis": "explicit",
          "source_id": "announcement",
          "note": "The supporting announcement is dated September 30, 2026."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T20:23:24Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Both maintainer publications read. This is source review, not independent reproduction or verification of deployed fixes."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/TanStack/router/security/advisories/GHSA-qx66-fv34-fjm8",
          "title": "Unauthenticated reflected XSS in TanStack Start server-function responses",
          "publisher": "TanStack",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T20:22:22Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "announcement",
          "url": "https://tanstack.com/blog/tanstack-start-security-update-cve-2026-102989",
          "title": "TanStack Start security update: CVE-2026-102989",
          "publisher": "TanStack",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T20:22:22Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Exposure requires an affected deployed server function and a visitor opening the supplied link. The described script authority is limited to that visitor's same-origin access; neither source provides a public demonstration transcript or evidence of production compromise or actual theft.",
        "Both sources give affected ranges beginning at 1.143.12, inclusive, and ending before each package's first patched version: @tanstack/react-start 1.168.60; @tanstack/solid-start 1.168.57; @tanstack/vue-start 1.168.56; @tanstack/start-server-core 1.169.39.",
        "The September 30 announcement states that patched packages were available by then; it does not establish a separate resource edition or each package's exact release date.",
        "GitHub identifies tannerlinsley as advisory publisher, not an explicit author byline; authors therefore remains empty. The supporting blog names Tanner Linsley. The advisory credits Lovable for helping discover and report the issue.",
        "This concerns reflected response authority, distinct from the library's Next.js Re:CACHE metadata and shared-cache case. No individual bounty amount is established. This educational record grants no testing authorization."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "typo3-2026-upload-validator-lifecycle-boundary",
      "title": "TYPO3: configured upload policy must reach the runtime validator",
      "publisher": "TYPO3",
      "authors": [
        "Oliver Hader"
      ],
      "primary_url": "https://news.typo3.com/security/advisory/typo3-core-sa-2026-020",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "web-foundations",
        "verification"
      ],
      "skillset_ids": [
        "untrusted-input-handling",
        "secure-parser-review",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-15305 concerns a lifecycle mismatch between form configuration and upload enforcement. MIME validation was registered before the concrete form properties were available, so the intended validator never entered the processing pipeline. The maintainer identifies TYPO3 14.2.0–14.3.4 as affected.",
      "defensive_use": "The official 14.3.5 release notes identify runtime registration of the MIME validator as the correction. Editorial lesson: a declared restriction is not evidence of enforcement. Trace configuration through construction and execution, and make absent policy enforcement a visible failure rather than an implicit success.",
      "prerequisites": [
        "Basic web upload handling and server-side validation",
        "Content-type interpretation and processing lifecycle concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and remediation references."
      },
      "dates": {
        "published": {
          "value": "2026-07-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Maintainer advisory publication."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational-resource edition established. Software fix chronology appears in caveats."
        },
        "source_displayed": {
          "value": "2026-07-14",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": "Publication date displayed on the advisory."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T12:09:10Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Read maintainer advisory and corroborating remediation references; no reproduction or independent patch testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://news.typo3.com/security/advisory/typo3-core-sa-2026-020",
          "title": "TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework",
          "publisher": "TYPO3",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:09:10Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://get.typo3.org/release-notes/14.3.5",
          "title": "TYPO3 14.3.5 Release Notes",
          "publisher": "TYPO3",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:09:10Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Exposure requires forms with file or image upload elements and configured MIME restrictions. The advisory reports acceptance of unintended MIME types, explicitly excluding PHP-file uploads; it does not establish server-side code execution or a production compromise.",
        "Sébastien Convers is credited as reporter; Josua Vogel and Oliver Hader are credited with fixing the issue.",
        "The official release notes date software version 14.3.5 to July 14, 2026. This happens to match advisory publication, but is a separate software-release event.",
        "Editorial remediation limit: correcting validator registration does not establish that every application-specific file policy, downstream processor or storage configuration is safe.",
        "Learning prerequisites and generalized design guidance are editorial. No award claim is made."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "umbraco-2026-group-assignment-authority",
      "title": "Umbraco: editing an account does not authorize assigning every role",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Jaroslav Lobačevski"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2026-065_Umbraco_CMS/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "CVE-2026-31834 separates authority over an account from authority to grant its roles. Research on Umbraco CMS 17.2.0 found that group-membership changes checked access to target users but omitted restrictions applied by the ordinary user-editing flow. A qualifying non-administrator API account could obtain administrator membership.",
      "defensive_use": "Editorial lesson: model both the target account and the proposed privilege as authorization inputs, using consistent policy across bulk and individual operations. The maintainer confirms the role-assignment defect and fixes in 16.5.1 and 17.2.2; upgrade affected installations rather than relying on interface restrictions.",
      "prerequisites": [
        "Basic server-side authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public disclosure readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-09-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource-edition release established. The research dates software fixes 16.5.1 and 17.2.2 to March 10, 2026, separately from its September publication."
        },
        "source_displayed": {
          "value": "2026-09-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T07:59:36Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Public primary disclosure reviewed; deployed remediation and source immutability were not established."
      },
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2026-065_Umbraco_CMS/",
          "title": "GHSL-2026-065: Unauthorized group assignment enables privilege escalation in Umbraco CMS",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:59:36Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "maintainer-advisory",
          "url": "https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-rhcg-3h8r-v6vp",
          "title": "Vertical Privilege Escalation via Missing Authorization Checks",
          "publisher": "Umbraco",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T07:59:36Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires an authenticated backoffice API user with access to the Users section. The vendor notes that this is ordinarily restricted to administrators, making custom delegation important to exposure.",
        "The research reports administrator membership; the vendor describes resulting administrative control. Neither source establishes a customer incident or exploitation prevalence.",
        "Research reported February 25, 2026; acknowledged as a duplicate the next day. The vendor advisory was published March 10; detailed research September 21.",
        "The maintainer lists affected versions as >=15.3.1, <17.2.1, while listing 16.5.1 and 17.2.2 as patched. These fields conflict; no corrected affected interval is inferred.",
        "The byline is Jaroslav Lobačevski; discovery is credited to the GitHub Security Lab Taskflow Agent with his manual verification. The maintainer credits odgrso separately. Learning prerequisites are editorial."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "usenix-2025-integration-platform-oauth-bindings",
      "title": "Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms",
      "publisher": "USENIX Association",
      "authors": [
        "Kaixuan Luo",
        "Xianbo Wang",
        "Pui Ho Adonis Fung",
        "Wing Cheong Lau",
        "Julien Lecomte"
      ],
      "primary_url": "https://www.usenix.org/conference/usenixsecurity25/presentation/luo-kaixuan",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "identity",
        "authorization",
        "cloud-security"
      ],
      "skillset_ids": [
        "integration-threat-modeling",
        "authorization-modeling",
        "identity-lifecycle-review"
      ],
      "version": "USENIX Security 2025",
      "summary": "Studies account linking across multi-app integration platforms and identifies inconsistent app identity as a trust-boundary problem. Proposes app-specific authorization-context binding.",
      "defensive_use": "Review whether an owned integration preserves the intended app and authorization issuer throughout account linking, including compatibility migrations.",
      "prerequisites": [
        "OAuth client and authorization-server roles",
        "Authorization response and session binding"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official open-access publication page and publisher-hosted prepublication paper."
      },
      "dates": {
        "published": {
          "value": "2025-08",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Month in the publisher’s proceedings citation; an earlier prepublication date is not established."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-02T17:12:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed the official publication record and relevant sections of its linked prepublication manuscript; no testing artifact was retrieved or executed."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.usenix.org/conference/usenixsecurity25/presentation/luo-kaixuan",
          "title": "Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms",
          "publisher": "USENIX Association",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T17:12:00Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "prepublication",
          "url": "https://www.usenix.org/system/files/conference/usenixsecurity25/sec24winter-prepub-332-luo.pdf",
          "title": "Publisher-hosted prepublication manuscript",
          "publisher": "USENIX Association",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-02T17:12:00Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Research measurements are historical, not a statement of current vendor exposure.",
        "The paper reports $35K across multiple vendors; no individual qualifying award is inferred.",
        "The final PDF exceeded retrieval limits. The official abstract, bibliography and prepublication defense/disclosure sections were reviewed."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "usenix-2025-tls-resumption-identity-isolation",
      "title": "STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets",
      "publisher": "USENIX Association",
      "authors": [
        "Sven Hebrok",
        "Tim Leonhard Storm",
        "Felix Matthias Cramer",
        "Maximilian Radoy",
        "Juraj Somorovsky"
      ],
      "primary_url": "https://www.usenix.org/conference/usenixsecurity25/presentation/hebrok",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "integration-threat-modeling",
        "security-token-design"
      ],
      "version": "USENIX Security 2025",
      "summary": "Studies a cross-layer authentication failure: shared TLS session-ticket infrastructure can preserve cryptographic session state without preserving the intended virtual-host identity and client-authentication policy. The authors connect that mismatch to inconsistent isolation during session resumption.",
      "defensive_use": "Document which authenticated identities and policy decisions must survive connection resumption in an owned hosting design. Review library contracts and remediation evidence for preserved identity context rather than assuming that an accepted session ticket establishes all application authority.",
      "prerequisites": [
        "TLS certificates and session resumption",
        "Virtual hosting and application routing"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official publication record and publisher-hosted paper were readable without an account at review time."
      },
      "dates": {
        "published": {
          "value": "2025-08",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Month in the publisher’s proceedings citation; not an inferred first online date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:41:45Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed the official publication record and publisher-hosted paper’s discussion, countermeasures, limitations, and conclusion. No research tooling was retrieved or run."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.usenix.org/conference/usenixsecurity25/presentation/hebrok",
          "title": "STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets",
          "publisher": "USENIX Association",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:41:45Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "paper",
          "url": "https://www.usenix.org/system/files/usenixsecurity25-hebrok.pdf",
          "title": "Publisher-hosted proceedings paper",
          "publisher": "USENIX Association",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:41:45Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "Measurements and vendor observations are historical, not evidence of present exposure.",
        "The study describes sampling and configuration limits; its findings are not exhaustive.",
        "This record summarizes identity invariants and countermeasures, not the paper’s testing procedures."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "usenix-2026-passkey-remediation-authority-lifecycle",
      "title": "Adversarial passkeys: account recovery must close every continuing source of authority",
      "publisher": "USENIX Association",
      "authors": [
        "Alaa Daffalla",
        "Grace Myers",
        "Rosanna Bellini",
        "Thomas Ristenpart",
        "Nicola Dell"
      ],
      "primary_url": "https://www.usenix.org/conference/usenixsecurity26/presentation/daffalla",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "identity-lifecycle-review",
        "approval-state-integrity",
        "defensive-evidence-writing"
      ],
      "version": "USENIX Security 2026 proceedings",
      "summary": "A qualitative lab study of 31 participants across three services found that unclear passkey labels, notifications and recovery interfaces obstructed complete account remediation. Conceptual boundary: proof that a recovery action completed does not establish that every independent credential or active session has lost authority.",
      "defensive_use": "Review an owned application’s recovery completion criteria across registered credentials, sessions and recovery channels. Make security interfaces explain what each revocation changes and what remains authorized; use clear credential provenance and action-specific notifications. Treat these as design-review questions, not evidence of a deployed fix.",
      "prerequisites": [
        "Passkey registration and relying-party credential records",
        "Session invalidation and account-recovery concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Publisher page and full paper were publicly readable at review."
      },
      "dates": {
        "published": {
          "value": "2026-08",
          "precision": "month",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publisher proceedings citation gives August 2026; first online publication day is not established."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T06:50:31Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed publisher metadata and paper findings, discussion and limitations. Proceedings edition identified; no separate revision date established."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.usenix.org/conference/usenixsecurity26/presentation/daffalla",
          "title": "“Maybe there’s only one passkey?”: Challenges Investigating and Remediating Adversarial Passkeys",
          "publisher": "USENIX Association",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:50:31Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "paper",
          "url": "https://www.usenix.org/system/files/usenixsecurity26-daffalla.pdf",
          "title": "Publisher-hosted proceedings paper",
          "publisher": "USENIX Association",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T06:50:31Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The simulated scenario presupposes earlier account access sufficient to register a credential; one service additionally required an email challenge. This is not a cryptographic break of passkeys or evidence of unauthenticated access.",
        "The paper reports that no participant completed all required remediation unaided. This demonstrates usability failures in controlled test accounts, not population-wide compromise rates or current service exposure.",
        "The small, single-city sample used researcher-provided devices and accounts; researcher assistance limits generalization of success rates.",
        "The authors explicitly label proposed interface improvements speculative and needing validation. Password reset, credential removal and session termination have distinct effects.",
        "This is a conference proceedings research paper, not a vendor patch advisory; no fixed-version claim is made."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "vendure-2026-payment-child-object-channel-authority",
      "title": "Vendure: payment child objects must inherit order channel authority",
      "publisher": "Vendure",
      "authors": [
        "michaelbromley"
      ],
      "primary_url": "https://github.com/vendurehq/vendure/security/advisories/GHSA-7qvr-c5vf-xxfh",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "integration-threat-modeling",
        "patch-verification"
      ],
      "version": null,
      "summary": "Order-level scoping did not carry into globally loaded payment, refund and fulfillment objects. A channel-limited administrator could affect another channel through child-object operations. The advisory contrasts scoped order reads with successful unauthorized refund processing, locating the failure at object-resolution and side-effect boundaries.",
      "defensive_use": "Editorial lesson: derive child-object authority from the parent order and current channel before any external effect. A later database rejection cannot reliably undo an earlier gateway action. Review alternate entry points against the same invariant, rather than assuming protected parent reads cover mutations.",
      "prerequisites": [
        "Basic authorization, application state machines and database transaction concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer evidence."
      },
      "dates": {
        "published": {
          "value": "2026-09-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-09-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:59:29Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Public primary evidence reviewed; no live testing or independent deployment verification."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/vendurehq/vendure/security/advisories/GHSA-7qvr-c5vf-xxfh",
          "title": "Cross-channel payment/refund IDOR — money movement across tenants (payment-side sibling of GHSA-frwg)",
          "publisher": "Vendure",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:59:29Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/vendurehq/vendure/releases/tag/v3.7.3",
          "title": "Vendure v3.7.3 release",
          "publisher": "Vendure",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:59:29Z",
          "supports": [
            "version",
            "dates",
            "summary"
          ]
        }
      ],
      "caveats": [
        "The reported setting is multi-channel commerce with channel-scoped order-update permission and suitable payment configuration. The advisory reports controlled refund evidence and potential financial disruption; production losses are not established.",
        "The advisory lists versions below 3.7.3 as affected and 3.7.3 as patched. Release notes confirm channel enforcement and advise upgrading related packages together.",
        "michaelbromley published the advisory; squinard1478 and raysabee are credited reporters. No CVE is assigned on the reviewed page.",
        "The release rendering displays September 2 without a year; no complete patch-release date is asserted. Resource edition and its release date remain null."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "vercel-react-router-2026-session-storage-key-authority",
      "title": "Vercel React Router: session identity must not select unrestricted storage authority",
      "publisher": "Vercel",
      "authors": [],
      "primary_url": "https://github.com/vercel/vercel/security/advisories/GHSA-7wjf-49rm-77gx",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "identity",
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "security-token-design",
        "authorization-modeling",
        "untrusted-input-handling",
        "patch-verification"
      ],
      "version": null,
      "summary": "GHSA-7wjf-49rm-77gx describes incoming session identifiers being used as storage keys without validation. Constrained generation did not constrain values returning from the client. The maintainer reports read, overwrite and delete authority within the application's Vercel KV namespace when @vercel/react-router 1.0.1 through 1.3.3 uses the optional KV session adapter with unsigned session cookies.",
      "defensive_use": "The maintainer lists 1.3.4 as fixed. Editorial lesson: distinguish identifier unpredictability, integrity of client-returned state, storage selection and authorization for each storage operation. A securely generated identifier does not prove that a later input was generated by the server. Keep session storage isolated from unrelated application state, validate the accepted identifier contract and require integrity protection appropriate to the session design. These are defensive principles, not a verified description of the patch implementation.",
      "prerequisites": [
        "Server-side session stores and cookie integrity concepts",
        "Key-value namespaces and operation-specific authorization concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer security advisory."
      },
      "dates": {
        "published": {
          "value": "2026-08-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication date; not an established software release or remediation date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-08-28",
          "precision": "day",
          "basis": "explicit",
          "source_id": "maintainer",
          "note": "Advisory publication date; not an established software release or remediation date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T16:19:24Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Maintainer advisory read. Affected and patched software versions are distinct from the unknown edition of this educational publication."
      },
      "sources": [
        {
          "id": "maintainer",
          "url": "https://github.com/vercel/vercel/security/advisories/GHSA-7wjf-49rm-77gx",
          "title": "Vercel React Router KV session-storage advisory GHSA-7wjf-49rm-77gx",
          "publisher": "Vercel",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T16:19:24Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The optional KV adapter and unsigned-cookie configuration are both required. The advisory does not establish exposure in every React Router application, platform-wide access or cross-customer access.",
        "No production incident, reward, finder, verified patch implementation or 1.3.4 release date is established by the reviewed advisory. It lists no known CVE. The publishing account is not treated as an author or finder.",
        "The linked filesystem-session advisory concerns a separate storage implementation; its mechanics and impact are not imported into this record."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "vercel-react2shell-parser-normalization-defense",
      "title": "React2Shell response: parser consistency and layered remediation",
      "publisher": "Vercel",
      "authors": [
        "Malte Ubl"
      ],
      "primary_url": "https://vercel.com/blog/our-million-dollar-hacker-challenge-for-react2shell",
      "resource_type_id": "architecture-guide",
      "topic_ids": [
        "web-foundations",
        "verification",
        "cloud-security"
      ],
      "skillset_ids": [
        "secure-parser-review",
        "untrusted-input-handling",
        "integration-threat-modeling",
        "patch-verification",
        "defensive-evidence-writing"
      ],
      "version": null,
      "summary": "Vercel’s retrospective describes request-inspection normalization, independent runtime restrictions, regression coverage and customer patching during its React2Shell response. It illustrates why a filter’s interpretation must align with application semantics.",
      "defensive_use": "In an owned architecture review, document each parser’s contract and residual assumptions. Pair input validation with independently enforced execution limits, maintain regression tests and verify application upgrades.",
      "prerequisites": [
        "HTTP request processing and serialization basics",
        "Application-runtime and defense-in-depth concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public article read without login."
      },
      "dates": {
        "published": {
          "value": "2025-12-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Article displays 19 Dec 2025."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2025-12-19",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Displayed article date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:51:20Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Historical vendor retrospective; review does not establish current protection coverage."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://vercel.com/blog/our-million-dollar-hacker-challenge-for-react2shell",
          "title": "Our $1 million hacker challenge for React2Shell",
          "publisher": "Vercel",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:51:20Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Vendor effectiveness claims are not independently audited.",
        "Mitigations buy time; they do not replace framework patches.",
        "This educational record establishes no individual bounty amount or testing authorization.",
        "The linked article includes operational material omitted here."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "vikunja-2026-favorites-current-access-revalidation",
      "title": "Vikunja: saved favorites must recheck current project access",
      "publisher": "Vikunja",
      "authors": [
        "kolaente"
      ],
      "primary_url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-jp29-jrxc-92vf",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "authorization",
        "business-logic"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "identity-lifecycle-review",
        "patch-verification"
      ],
      "version": null,
      "prerequisites": [
        "Basic server-side authorization and persistent-state concepts"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary disclosure readable without an account."
      },
      "dates": {
        "published": {
          "value": "2026-08-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        },
        "source_displayed": {
          "value": "2026-08-31",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T12:29:14Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary advisory and maintainer remediation evidence reviewed; no target testing or deployment verification performed."
      },
      "content_scope": "defensive_education",
      "summary": "GHSA-jp29-jrxc-92vf describes a task-search branch that trusted a saved favorite without checking current project access. Favorite records survived share revocation, allowing previously authorized collaborators to keep reading selected tasks through search despite denial by direct task reads.",
      "defensive_use": "Editorial lesson: saved associations express preference, not continuing authority. Every query branch returning an object should enforce its current authorization policy, including alternate views and aggregates. The advisory lists 2.6.0 as patched; the August 31, 2026 maintainer release article separately confirms this revocation issue was fixed.",
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-jp29-jrxc-92vf",
          "title": "Favorited tasks remain readable after project access is revoked",
          "publisher": "Vikunja",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:29:14Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://vikunja.io/changelog/vikunja-2.6.0-was-released/",
          "title": "Vikunja 2.6.0: Eighteen security fixes, Planka import, and attachment previews",
          "publisher": "Vikunja",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T12:29:14Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Requires prior write-level sharing and a favorite saved while authorized, followed by revocation. The advisory lists versions through 2.5.0 as affected and reports runtime verification on 2.5.0.",
        "Reported observation: titles and descriptions edited after revocation remained readable. Impact is read-only and limited to previously favorited tasks; it does not establish access to all project tasks or a production incident.",
        "Published August 31, 2026 by kolaente; JellowBeanz26 is credited as reporter. Software release 2.6.0 was announced the same day in the separate maintainer article; this is not a resource-edition date.",
        "The advisory proposes current-access filtering and/or favorite cleanup. Neither reviewed source establishes the exact implemented combination, so these proposals are not represented as verified patch internals."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "vvveb-2026-order-domain-invariant",
      "title": "Vvveb: numeric input validity does not establish legitimate order state",
      "publisher": "Vvveb",
      "authors": [],
      "primary_url": "https://github.com/givanz/Vvveb/security/advisories/GHSA-75x2-j47j-mg8j",
      "resource_type_id": "maintainer-advisory",
      "topic_ids": [
        "business-logic",
        "verification"
      ],
      "skillset_ids": [
        "approval-state-integrity",
        "untrusted-input-handling",
        "defensive-evidence-writing"
      ],
      "version": null,
      "summary": "CVE-2026-44826 concerns missing domain constraints between cart quantities and authoritative orders. Arithmetic propagated invalid purchase state through totals and checkout. The maintainer-published report describes a validated run producing a persisted negative-total order, distinguishing a durable integrity failure from an incorrect display.",
      "defensive_use": "Editorial reasoning: trace domain invariants across every transition that makes provisional state authoritative. Require valid quantities during cart mutation and revalidate order constraints at commitment. Keep legitimate credit workflows distinct from purchases. The advisory proposes these checks; release 1.0.8.2 explicitly lists the corresponding repair.",
      "prerequisites": [
        "Basic understanding of checkout state, numeric validation and database integrity"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public maintainer advisory and release notes."
      },
      "dates": {
        "published": {
          "value": "2026-05-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate educational edition identified."
        },
        "source_displayed": {
          "value": "2026-05-04",
          "precision": "day",
          "basis": "explicit",
          "source_id": "advisory",
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-04T02:37:10Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Advisory and release notes reviewed; no vulnerability reproduction or live testing."
      },
      "sources": [
        {
          "id": "advisory",
          "url": "https://github.com/givanz/Vvveb/security/advisories/GHSA-75x2-j47j-mg8j",
          "title": "Vvveb CMS — Negative-quantity cart manipulation allows creation of orders with negative grand totals",
          "publisher": "Vvveb",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T02:32:36Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "release",
          "url": "https://github.com/givanz/Vvveb/releases/tag/1.0.8.2",
          "title": "Vvveb 1.0.8.2",
          "publisher": "Vvveb",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-04T02:36:20Z",
          "supports": [
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "The advisory lists versions through 1.0.8 as affected and 1.0.8.2 as patched; it does not explicitly classify intervening 1.0.8.1.",
        "The reported setting permits guest checkout without special extensions. External accounting, inventory or payment consequences depend on integration behavior; actual payouts or production losses are not demonstrated.",
        "The release page displays May 4 without a year in the retrieved rendering. No full software-release date is asserted, and patch version is not an educational edition.",
        "The advisory is published by the givanz account. Its Discoverer Credit section names Basant Kumar as primary discoverer and Hamed Kohi as co-discoverer; these roles do not establish advisory authorship, so named authors remain unestablished. Original analysis here is limited to defensive design lessons."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "w3c-2026-trusted-types-policy-authority",
      "title": "Trusted Types: typed sinks depend on trustworthy policy creation",
      "publisher": "World Wide Web Consortium",
      "authors": [
        "Krzysztof Kotowicz"
      ],
      "primary_url": "https://www.w3.org/TR/2026/WD-trusted-types-20260623/",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "web-foundations"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "untrusted-input-handling",
        "secure-parser-review"
      ],
      "version": "Working Draft, 23 June 2026",
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public primary-source guidance."
      },
      "content_scope": "defensive_education",
      "summary": "Defines a browser-enforced boundary between ordinary strings and typed values accepted by injection-sensitive APIs. The underlying failure is allowing untrusted text to acquire executable interpretation. Policies centralize creation of accepted values; matching types preserve intended use, but do not independently establish that a policy's transformation is safe.",
      "defensive_use": "Editorial reasoning: review two invariants separately: sensitive consumers accept only policy-produced values, and each producer enforces an adequate trust contract. Minimize policy creation authority, keep policy dependencies reviewable and avoid global state silently changing decisions. The maintainer FAQ explains why sanitization must be consistently applied, rather than merely available in a library.",
      "prerequisites": [
        "JavaScript DOM data flow and Content Security Policy"
      ],
      "dates": {
        "published": {
          "value": "2022-09-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "history",
          "note": "First Public Working Draft of the specification series."
        },
        "version_released": {
          "value": "2026-06-23",
          "precision": "day",
          "basis": "explicit",
          "source_id": "standard",
          "note": "Date of the reviewed educational specification edition."
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T15:20:45Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed the dated draft, publication history and explanatory FAQ; no conformance tests were run."
      },
      "sources": [
        {
          "id": "standard",
          "url": "https://www.w3.org/TR/2026/WD-trusted-types-20260623/",
          "title": "Trusted Types",
          "publisher": "World Wide Web Consortium",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:20:45Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "history",
          "url": "https://www.w3.org/standards/history/trusted-types/",
          "title": "Trusted Types publication history",
          "publisher": "World Wide Web Consortium",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:20:45Z",
          "supports": [
            "dates"
          ]
        },
        {
          "id": "faq",
          "url": "https://github.com/w3c/trusted-types/wiki/FAQ",
          "title": "Trusted Types FAQ",
          "publisher": "W3C Trusted Types project",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T15:20:45Z",
          "supports": [
            "summary"
          ]
        }
      ],
      "caveats": [
        "The reviewed edition is a Working Draft, not a final W3C Recommendation. Krzysztof Kotowicz is its listed editor; Mike West is listed as former editor.",
        "Unsafe policies can preserve DOM injection risk. The design does not isolate actively malicious first-party code or guard every DOM operation.",
        "The FAQ distinguishes client-side sink controls from server-generated injection and complementary CSP defenses. Its 2021 browser-support discussion is historical and is not used as current compatibility evidence."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "w3c-fetch-metadata-request-context-boundaries",
      "title": "Fetch Metadata Request Headers",
      "publisher": "World Wide Web Consortium",
      "authors": [
        "Mike West"
      ],
      "primary_url": "https://www.w3.org/TR/2026/WD-fetch-metadata-20260921/",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "integration-threat-modeling"
      ],
      "version": "Working Draft, 21 September 2026",
      "summary": "Defines browser-provided request context covering site relationship, destination, mode, and user activation. Explains how redirect history affects that context and why context-dependent responses need matching cache behavior. This supports reasoning about which browser interactions an application intends to accept.",
      "defensive_use": "Review an owned service’s documented request-context policy, including redirects, legitimate cross-origin use, and caching. Treat browser context as an additional policy input rather than proof of a user’s resource permissions.",
      "prerequisites": [
        "HTTP requests and response caching",
        "Same-origin and same-site distinctions"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official specification readable without an account at review time."
      },
      "dates": {
        "published": {
          "value": "2019-06-27",
          "precision": "day",
          "basis": "explicit",
          "source_id": "publication-history",
          "note": "Date of the First Public Working Draft in W3C’s publication history; the reviewed edition was published separately on 2026-09-21."
        },
        "version_released": {
          "value": "2026-09-21",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Publication date of the reviewed Working Draft; not the origin date of the specification series."
        },
        "source_displayed": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": null
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T04:49:39Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Reviewed this identified edition and its relevant design and security sections. Retrieval date is separate from publication; later revisions or errata may exist."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://www.w3.org/TR/2026/WD-fetch-metadata-20260921/",
          "title": "Fetch Metadata Request Headers",
          "publisher": "World Wide Web Consortium",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:40:00Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        },
        {
          "id": "publication-history",
          "url": "https://www.w3.org/standards/history/fetch-metadata/",
          "title": "Fetch Metadata Request Headers publication history",
          "publisher": "World Wide Web Consortium",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T04:49:18Z",
          "supports": [
            "dates"
          ]
        }
      ],
      "caveats": [
        "The reviewed edition is a Working Draft, not a final W3C Recommendation.",
        "The draft does not establish support in every deployed browser or non-browser client."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "w3c-permissions-policy-embedded-feature-authority",
      "title": "Permissions Policy: inherited browser-feature authority across embedded documents",
      "publisher": "World Wide Web Consortium",
      "authors": [
        "Ian Clelland",
        "Ari Chivukula"
      ],
      "primary_url": "https://w3c.github.io/webappsec-permissions-policy/",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "integration-threat-modeling"
      ],
      "version": "Editor's Draft, 22 September 2026",
      "summary": "Defines browser-feature availability through inherited restrictions, document declarations and frame delegation. Feature defaults govern undeclared cases; a child cannot restore authority disabled by its parent.",
      "defensive_use": "Editorial guidance: document which component owns each capability decision and distinguish intended delegation from effective restrictions. Keep browser-feature controls separate from application authorization and user consent in integration reviews.",
      "prerequisites": [
        "Browser origins, embedded documents and HTTP response headers"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public specification draft."
      },
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Original publication date not established in this review."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Living editor's draft; no released edition established."
        },
        "source_displayed": {
          "value": "2026-09-22",
          "precision": "day",
          "basis": "explicit",
          "source_id": "standard",
          "note": "Displayed draft date, not original publication or a released edition."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T21:42:00Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Read the official draft's status, framework, delivery and introspection sections; no browser conformance testing."
      },
      "sources": [
        {
          "id": "standard",
          "url": "https://w3c.github.io/webappsec-permissions-policy/",
          "title": "Permissions Policy",
          "publisher": "World Wide Web Consortium",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T21:41:20Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "Work in progress, not a final Recommendation or deployed-compatibility guarantee. Listed authors are the draft's editors.",
        "User agents need not support every feature. Frame-level observable policy omits child response policy and later navigation, so it does not establish the loaded document's effective access.",
        "Complements iframe sandboxing; it is not a complete isolation model."
      ],
      "content_scope": "defensive_education"
    },
    {
      "schema_version": "1.0.0",
      "id": "whatwg-coop-opener-and-origin-authority",
      "title": "HTML COOP: opener separation and same-origin authority",
      "publisher": "WHATWG",
      "authors": [],
      "primary_url": "https://html.spec.whatwg.org/multipage/browsers.html#cross-origin-opener-policies",
      "resource_type_id": "technical-standard",
      "topic_ids": [
        "web-foundations",
        "authorization"
      ],
      "skillset_ids": [
        "browser-isolation-review",
        "integration-threat-modeling"
      ],
      "version": "HTML Living Standard (reviewed 2026-10-03)",
      "prerequisites": [
        "Browser origin and navigation concepts",
        "HTTP session and response-cache fundamentals"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Official documentation readable without an account at review time."
      },
      "content_scope": "defensive_education",
      "summary": "Defines how opener policies affect browsing-context separation during navigation. The standard expressly distinguishes severing an opener relationship from a robust boundary between same-origin documents: storage, service workers, messaging and server responses can preserve shared authority.",
      "defensive_use": "Model window references separately from origin-wide data and service authority. For an owned application, document every shared client capability and server data path before relying on opener separation; combine appropriate embedding, cookie and response controls with an explicit trust-domain design.",
      "dates": {
        "published": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "The reviewed section does not establish its original publication date."
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "Living specification without a separately identified release for this section."
        },
        "source_displayed": {
          "value": "2026-10-02",
          "precision": "day",
          "basis": "explicit",
          "source_id": "primary",
          "note": "Displayed last-updated date for the HTML Living Standard; not proof this section changed on that date."
        }
      },
      "freshness": {
        "reviewed_at": "2026-10-03T05:39:10Z",
        "living_resource": true,
        "status": "primary_source_reviewed",
        "note": "Reviewed the current opener-policy definitions and same-origin limitations. The page remains mutable and is not an immutable versioned edition."
      },
      "sources": [
        {
          "id": "primary",
          "url": "https://html.spec.whatwg.org/multipage/browsers.html#cross-origin-opener-policies",
          "title": "HTML Standard: Cross-origin opener policies",
          "publisher": "WHATWG",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T05:39:10Z",
          "supports": [
            "summary",
            "version",
            "dates"
          ]
        }
      ],
      "caveats": [
        "A specification defines intended behavior; this review does not establish per-value support in deployed browsers.",
        "Opener separation alone does not partition origin-wide storage or grant application-level authorization.",
        "This resource complements message validation and request-context resources by modeling the isolation boundary itself."
      ]
    },
    {
      "schema_version": "1.0.0",
      "id": "zammad-2026-asset-serialization-group-authorization",
      "title": "Zammad: overridden serialization must preserve group authorization",
      "publisher": "GitHub Security Lab",
      "authors": [
        "Man Yue Mo"
      ],
      "primary_url": "https://securitylab.github.com/advisories/GHSL-2026-049_Zammad/",
      "resource_type_id": "research-paper",
      "topic_ids": [
        "authorization",
        "web-foundations"
      ],
      "skillset_ids": [
        "authorization-modeling",
        "patch-verification"
      ],
      "version": null,
      "prerequisites": [
        "Basic understanding of server-side object authorization and resource ownership"
      ],
      "prerequisites_basis": "editorial_guidance",
      "access": {
        "cost": "free",
        "note": "Public sources readable without an account."
      },
      "freshness": {
        "reviewed_at": "2026-10-03T13:10:00Z",
        "living_resource": false,
        "status": "primary_source_reviewed",
        "note": "Primary disclosure and maintainer evidence reviewed; no deployment inspection or vulnerability testing performed."
      },
      "content_scope": "defensive_education",
      "dates": {
        "published": {
          "value": "2026-03-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "source_displayed": {
          "value": "2026-03-06",
          "precision": "day",
          "basis": "explicit",
          "source_id": "research",
          "note": null
        },
        "version_released": {
          "value": null,
          "precision": null,
          "basis": "not_reported",
          "source_id": null,
          "note": "No separate resource edition is stated; software fix chronology is recorded in caveats."
        }
      },
      "summary": "GHSL-2026-049 describes a ticket asset serializer that overrode a permission-aware base implementation without preserving its group-access check. GitHub Security Lab reports confidential ticket and associated-user disclosure in tested Zammad 6.5.2; the vendor corroborates unauthorized asset access.",
      "defensive_use": "Editorial lesson: a model override must retain the security contract of its base implementation. Bind serialization to the requesting actor and the resource group before response construction; review inherited and specialized serializers together.",
      "caveats": [
        "The case requires an authenticated agent-role user. Documented impact is reading tickets and associated information outside permitted groups. The research summary mentions possible manipulation, but its impact section and vendor notice substantiate disclosure; this record makes no demonstrated-write claim.",
        "GitHub Security Lab reported February 17, 2026; the maintainer identified it as a duplicate February 18. GHSL credits Taskflow Agent discovery with manual verification by Peter Stöckli and Man Yue Mo. Vendor ZAA-2026-05 credits Sho Odagiri of GMO Cybersecurity; preserve both attributions.",
        "Vendor ZAA-2026-05 displays March 4, 2026 above a February 25 advisory-detail date. It lists fixes in 7.0.0 and 6.5.3 and says SaaS remediation was handled. GHSL dates the 7.0.0 patch release March 4. A release-specific date for 6.5.3 is not established here.",
        "The reviewed notice still says CVE assignment pending. No bounty amount, customer incident count, or independent deployment verification is supplied. Learning prerequisites and design lessons are editorial."
      ],
      "sources": [
        {
          "id": "research",
          "url": "https://securitylab.github.com/advisories/GHSL-2026-049_Zammad/",
          "title": "GHSL-2026-049: An Insecure Direct Object Reference (IDOR) in Zammad Leads to Access Control Violations",
          "publisher": "GitHub Security Lab",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        },
        {
          "id": "vendor",
          "url": "https://zammad.com/en/advisories/zaa-2026-05",
          "title": "Security Advisory ZAA-2026-05",
          "publisher": "Zammad",
          "provenance": "official_primary",
          "retrieved_at": "2026-10-03T13:10:00Z",
          "supports": [
            "summary",
            "dates"
          ]
        }
      ]
    }
  ],
  "diagrams": [
    {
      "schema_version": "1.0.0",
      "id": "account-recovery-challenge-lifecycle",
      "title": "Recovery must preserve account ownership",
      "alt_text": "A limited recovery request creates an account-bound challenge. Only valid, unexpired, unused proof permits a reset. Failure preserves account state; success consumes the challenge and notifies the owner.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.",
      "linked_report_ids": [
        "gitlab-recovery-address-binding-cve-2023-7028",
        "microsoft-account-recovery-rate-limit-consistency-2021",
        "instagram-recovery-challenge-account-binding-2019"
      ],
      "linked_resource_ids": [
        "owasp-account-recovery-state-integrity"
      ],
      "evidence_urls": [
        "https://hackerone.com/reports/2293343",
        "https://thezerohack.com/how-i-might-have-hacked-any-microsoft-account",
        "https://thezerohack.com/hack-instagram-again",
        "https://cheatsheetseries.owasp.org/cheatsheets/Forgot_Password_Cheat_Sheet.html"
      ],
      "reviewed_at": "2026-10-02T16:59:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "request",
            "label": "Limit requests; keep responses private",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "challenge",
            "label": "Bind unpredictable, expiring challenge to account",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "validate",
            "label": "Correct account, unused proof, valid time and attempt policy?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "unchanged",
            "label": "Reject; preserve account state",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "reset",
            "label": "Consume challenge and reset password",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "notify",
            "label": "Notify owner; apply session policy and normal sign-in",
            "shape": "box",
            "kind": "data"
          }
        ],
        "edges": [
          {
            "from": "request",
            "to": "challenge",
            "label": null
          },
          {
            "from": "challenge",
            "to": "validate",
            "label": null
          },
          {
            "from": "validate",
            "to": "unchanged",
            "label": "No"
          },
          {
            "from": "validate",
            "to": "reset",
            "label": "Yes"
          },
          {
            "from": "reset",
            "to": "notify",
            "label": null
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/account-recovery-challenge-lifecycle.mmd",
        "graphviz": "diagrams/account-recovery-challenge-lifecycle.dot",
        "svg": "diagrams/account-recovery-challenge-lifecycle.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "ai-content-authority-separation",
      "title": "Retrieved content is data, not authority",
      "alt_text": "User intent and untrusted connector content enter the AI workflow separately. A proposed action reaches an independent policy decision. Only an authorized state change proceeds; otherwise state remains unchanged.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.",
      "linked_report_ids": [
        "google-gemini-enterprise-connected-content-memory-integrity-2026",
        "google-gemini-colab-rendering-boundary-2025"
      ],
      "linked_resource_ids": [
        "owasp-llm-prompt-injection-prevention"
      ],
      "evidence_urls": [
        "https://dev.to/behi_sec/google-paid-me-15000-for-this-prompt-injection-bug-5fn6",
        "https://buganizer.cc/hacking-gemini-a-multi-layered-approach-md/",
        "https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html"
      ],
      "reviewed_at": "2026-10-02T14:50:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "user",
            "label": "User intent and approved scope",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "data",
            "label": "Retrieved connector content: untrusted data",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "model",
            "label": "AI proposes a response or action",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "policy",
            "label": "Does independent policy authorize the action?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "change",
            "label": "Apply only the approved state change",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "deny",
            "label": "Keep state unchanged",
            "shape": "box",
            "kind": "denied"
          }
        ],
        "edges": [
          {
            "from": "user",
            "to": "model",
            "label": "Intent"
          },
          {
            "from": "data",
            "to": "model",
            "label": "Content"
          },
          {
            "from": "model",
            "to": "policy",
            "label": "Proposal"
          },
          {
            "from": "policy",
            "to": "change",
            "label": "Yes"
          },
          {
            "from": "policy",
            "to": "deny",
            "label": "No"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/ai-content-authority-separation.mmd",
        "graphviz": "diagrams/ai-content-authority-separation.dot",
        "svg": "diagrams/ai-content-authority-separation.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "approval-version-integrity",
      "title": "Approval stays attached to the reviewed version",
      "alt_text": "Reviewed content and its immutable version are bound to an approval. Execution independently checks that the version still matches. Matching requests proceed with least privilege; mismatches require a new review.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.",
      "linked_report_ids": [
        "google-cloud-build-approval-toctou-2025",
        "github-actions-reference-validation-2021"
      ],
      "linked_resource_ids": [
        "owasp-authorization-cheat-sheet",
        "owasp-transaction-authorization-state-integrity"
      ],
      "evidence_urls": [
        "https://adnanthekhan.com/posts/cloud-build-toctou/",
        "https://blog.teddykatz.com/2021/03/17/github-actions-write-access.html",
        "https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html",
        "https://cheatsheetseries.owasp.org/cheatsheets/Transaction_Authorization_Cheat_Sheet.html"
      ],
      "reviewed_at": "2026-10-02T16:39:51Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "review",
            "label": "Review content and immutable version",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "approval",
            "label": "Record approval for that version",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "check",
            "label": "Does execution match the approved version?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "run",
            "label": "Allow least-privilege execution",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "stop",
            "label": "Stop and request a new review",
            "shape": "box",
            "kind": "denied"
          }
        ],
        "edges": [
          {
            "from": "review",
            "to": "approval",
            "label": null
          },
          {
            "from": "approval",
            "to": "check",
            "label": null
          },
          {
            "from": "check",
            "to": "run",
            "label": "Yes"
          },
          {
            "from": "check",
            "to": "stop",
            "label": "No"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/approval-version-integrity.mmd",
        "graphviz": "diagrams/approval-version-integrity.dot",
        "svg": "diagrams/approval-version-integrity.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "browser-message-authority-boundaries",
      "title": "Browser messages need separate trust checks",
      "alt_text": "An incoming browser message first passes origin, sender-context and format validation. A separate decision checks the operation and recipient. Failed checks reject the message without disclosure or state change. Approved content remains data and only the permitted action is performed.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Original defensive model combining OWASP messaging and authorization guidance with the linked historical cases. These are independent design checks, not a vendor patch diagram or an operational reproduction.",
      "linked_report_ids": [
        "facebook-sdk-message-authentication-randomness-2023",
        "meta-pixel-cross-window-authority-binding-2024"
      ],
      "linked_resource_ids": [
        "owasp-browser-message-trust-boundaries",
        "owasp-authorization-cheat-sheet"
      ],
      "evidence_urls": [
        "https://cheatsheetseries.owasp.org/cheatsheets/HTML5_Security_Cheat_Sheet.html",
        "https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html",
        "https://ysamm.com/uncategorized/2026/01/16/leaking-fbevents-ato.html",
        "https://ysamm.com/uncategorized/2026/01/17/math-random-facebook-sdk.html"
      ],
      "reviewed_at": "2026-10-02T19:49:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "message",
            "label": "Incoming browser message",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "validate",
            "label": "Origin, sender context and format valid?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "authorize",
            "label": "Operation and recipient allowed?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "reject",
            "label": "Reject; no disclosure or state change",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "data",
            "label": "Keep accepted content as data",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "allow",
            "label": "Perform only the permitted action",
            "shape": "box",
            "kind": "allowed"
          }
        ],
        "edges": [
          {
            "from": "message",
            "to": "validate",
            "label": null
          },
          {
            "from": "validate",
            "to": "reject",
            "label": "No"
          },
          {
            "from": "validate",
            "to": "authorize",
            "label": "Yes"
          },
          {
            "from": "authorize",
            "to": "reject",
            "label": "No"
          },
          {
            "from": "authorize",
            "to": "data",
            "label": "Yes"
          },
          {
            "from": "data",
            "to": "allow",
            "label": null
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/browser-message-authority-boundaries.mmd",
        "graphviz": "diagrams/browser-message-authority-boundaries.dot",
        "svg": "diagrams/browser-message-authority-boundaries.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "build-artifact-provenance-boundary",
      "title": "Build evidence must match the artifact and trusted builder",
      "alt_text": "Untrusted contributions remain separated from trusted build state. An artifact and its provenance reach a consumer policy gate. Only authenticated evidence matching the artifact and expected builder and inputs makes it eligible for release review; missing or mismatched evidence prevents promotion.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model combining the Angular case with SLSA build guidance. The case supports separating automation trust and shared build state; the consumer verification gate is a general design synthesis, not a reconstruction of Angular remediation. Assumes a defined trust policy for builders and provenance. Provenance presence alone does not establish authenticity, and passing these checks does not prove the software is free of vulnerabilities.",
      "linked_report_ids": [
        "angular-ci-cache-trust-2026"
      ],
      "linked_resource_ids": [
        "slsa-v1-2-supply-chain-build-provenance"
      ],
      "evidence_urls": [
        "https://adnanthekhan.com/posts/angular-compromise-through-dev-infra/",
        "https://slsa.dev/spec/v1.2/build-track-basics",
        "https://slsa.dev/spec/v1.2/build-provenance"
      ],
      "reviewed_at": "2026-10-03T18:32:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "inputs",
            "label": "Contributions carry explicit trust level",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "builder",
            "label": "Separate trusted build state from untrusted input",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "artifact",
            "label": "Artifact plus build provenance",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "verify",
            "label": "Authenticated evidence matches artifact and expected build?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "deny",
            "label": "Hold artifact if evidence is missing or mismatched",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "review",
            "label": "Eligible for remaining release review",
            "shape": "box",
            "kind": "allowed"
          }
        ],
        "edges": [
          {
            "from": "inputs",
            "to": "builder",
            "label": null
          },
          {
            "from": "builder",
            "to": "artifact",
            "label": null
          },
          {
            "from": "artifact",
            "to": "verify",
            "label": null
          },
          {
            "from": "verify",
            "to": "deny",
            "label": "No"
          },
          {
            "from": "verify",
            "to": "review",
            "label": "Yes"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/build-artifact-provenance-boundary.mmd",
        "graphviz": "diagrams/build-artifact-provenance-boundary.dot",
        "svg": "diagrams/build-artifact-provenance-boundary.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "combined-view-source-authorization",
      "title": "Combined views preserve every source's access boundary",
      "alt_text": "A caller requests a combined view using required source A and required source B. Each source has its own authorization decision for that caller. Either No denies the combined view without protected source data. Both Yes decisions are required at an explicit AND gate before composition. Field selection preserves each source’s field permissions, and only permitted data is returned.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Original conceptual model for a view that requires multiple independently protected sources. Permission to use one source cannot authorize another source. The convergence is an AND requirement: both source decisions must permit the requesting actor before composition. GitHub’s comparison disclosure supports the cross-repository boundary; Frappe’s linked-document disclosure supports independent document permissions and field selection. OWASP provides the general per-request and deny-by-default guidance. The graph assumes an all-or-nothing response contract. Applications supporting partial results need a separately specified non-disclosing omission policy. Field selection remains a distinct requirement even when every source check permits access. This is not either vendor’s architecture or patch implementation. Snapshot consistency, permission-change races and inference from combined values are outside this model.",
      "linked_report_ids": [
        "github-cross-repository-comparison-authorization-2025"
      ],
      "linked_resource_ids": [
        "frappe-2026-linked-document-response-authorization",
        "owasp-authorization-cheat-sheet"
      ],
      "evidence_urls": [
        "https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.5",
        "https://securitylab.github.com/advisories/GHSL-2026-012_Frappe/",
        "https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html"
      ],
      "reviewed_at": "2026-10-04T07:15:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "source-a",
            "label": "Required source A and its access policy",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "caller",
            "label": "Caller requests a combined view",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "source-b",
            "label": "Required source B and its access policy",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "authorize-a",
            "label": "Caller permitted to use source A?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "authorize-b",
            "label": "Caller permitted to use source B?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "deny-a",
            "label": "Deny combined view; no protected source data",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "compose",
            "label": "AND: both checks permit; compose view",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "deny-b",
            "label": "Deny combined view; no protected source data",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "project",
            "label": "Select fields permitted from each source",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "response",
            "label": "Return only permitted data",
            "shape": "box",
            "kind": "allowed"
          }
        ],
        "edges": [
          {
            "from": "source-a",
            "to": "authorize-a",
            "label": null
          },
          {
            "from": "caller",
            "to": "authorize-a",
            "label": null
          },
          {
            "from": "caller",
            "to": "authorize-b",
            "label": null
          },
          {
            "from": "source-b",
            "to": "authorize-b",
            "label": null
          },
          {
            "from": "authorize-a",
            "to": "deny-a",
            "label": "No"
          },
          {
            "from": "authorize-b",
            "to": "deny-b",
            "label": "No"
          },
          {
            "from": "authorize-a",
            "to": "compose",
            "label": "Yes"
          },
          {
            "from": "authorize-b",
            "to": "compose",
            "label": "Yes"
          },
          {
            "from": "compose",
            "to": "project",
            "label": null
          },
          {
            "from": "project",
            "to": "response",
            "label": null
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/combined-view-source-authorization.mmd",
        "graphviz": "diagrams/combined-view-source-authorization.dot",
        "svg": "diagrams/combined-view-source-authorization.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "delegated-grant-authority-continuity",
      "title": "Delegated authority stays within the approved grant",
      "alt_text": "Approved grant context, including subject, client, permitted resources and actions, and a first-issuance or renewal request are both required inputs. Resolve trusted grant context and check that the grant and client are correct and requested authority remains within approval. Issue only bounded authority when all checks pass. Do not issue on mismatch or incomplete binding. Changing the approved authority requires a separate authorization decision; no automatic-consent loop is shown.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Original editorial defensive synthesis, not a vendor architecture, protocol sequence or independently verified patch. The Google researcher describes lost client and permission binding through a device grant; proposed binding controls are not evidence of the deployed repair. The n8n maintainer describes constrained first issuance but missing resource binding during refresh, with a stated repair that retains the binding and rejects mismatches. It also calls for renewed authorization of older unbound grants. RFC 9700 sections 2.3 and 4.14.2 support restricted token authority and refresh grants bound to the consented scope and resource servers. The graph abstracts one invariant shared by distinct first-issuance and refresh paths; it does not equate their protocol steps. Both input arrows are required together, not alternative authorization paths. Trusted context means authenticated, integrity-protected grant information and applicable client verification; no storage design is prescribed. The subject's wider access and a client's registration are not extra authority delegated by this grant. Within approval permits narrower issuance and authority added through a separately approved incremental decision; it does not require exact equality with every original permission. Resources, audiences and actions have deployment-specific meanings. Mismatched or incomplete binding cannot establish approval. A separate authorization decision is needed to change approved authority, with no automatic consent or retry loop implied. Revocation, concurrency, replay protection and consent usability are outside this model.",
      "linked_report_ids": [
        "google-device-authorization-client-scope-binding-2026"
      ],
      "linked_resource_ids": [
        "n8n-2026-refresh-grant-resource-binding",
        "rfc-9700-oauth-security-best-current-practice"
      ],
      "evidence_urls": [
        "https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html",
        "https://github.com/n8n-io/n8n/security/advisories/GHSA-cw9w-vv67-hf73",
        "https://www.rfc-editor.org/rfc/rfc9700.html"
      ],
      "reviewed_at": "2026-10-04T20:44:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "approved-grant",
            "label": "Approved grant: subject, client, resources and actions",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "request",
            "label": "First issuance or renewal request",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "resolve",
            "label": "Resolve trusted grant context",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "check",
            "label": "Correct grant/client AND requested authority within approval?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "issue",
            "label": "Issue authority bounded by the approved grant",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "stop",
            "label": "Do not issue authority from this request",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "separate-decision",
            "label": "Changing approved authority needs a separate authorization decision",
            "shape": "box",
            "kind": "data"
          }
        ],
        "edges": [
          {
            "from": "approved-grant",
            "to": "resolve",
            "label": "Required input"
          },
          {
            "from": "request",
            "to": "resolve",
            "label": "Required input"
          },
          {
            "from": "resolve",
            "to": "check",
            "label": null
          },
          {
            "from": "check",
            "to": "issue",
            "label": "Yes"
          },
          {
            "from": "check",
            "to": "stop",
            "label": "No or incomplete binding"
          },
          {
            "from": "stop",
            "to": "separate-decision",
            "label": "If a different grant is needed"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/delegated-grant-authority-continuity.mmd",
        "graphviz": "diagrams/delegated-grant-authority-continuity.dot",
        "svg": "diagrams/delegated-grant-authority-continuity.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "error-diagnostic-disclosure-boundary",
      "title": "Failures need separate public and diagnostic contracts",
      "alt_text": "A failure reaches a shared error handler. The public response contains minimal generic information. A separate diagnostic path selects useful context, removes secrets and unnecessary personal data, and stores it under access and retention controls. Raw exception details do not flow directly to the client.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model derived from the Facebook error-response case and OWASP error-handling and logging guidance. The case establishes unintended response disclosure and broader framework remediation; diagnostic minimization and retention are general guidance, not claims about the vendor patch. Assumes an application-defined public error contract and an authorized diagnostic purpose. This model does not establish preserved authorization in fallback behavior or independent proof from logs.",
      "linked_report_ids": [
        "facebook-error-response-data-isolation-2019"
      ],
      "linked_resource_ids": [
        "owasp-error-response-data-minimization",
        "owasp-security-logging-evidence-quality"
      ],
      "evidence_urls": [
        "https://about.fb.com/ltam/news/2020/02/una-mirada-retrospectiva-a-los-aspectos-mas-destacados-de-bug-bounty-2019/",
        "https://cheatsheetseries.owasp.org/cheatsheets/Error_Handling_Cheat_Sheet.html",
        "https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html"
      ],
      "reviewed_at": "2026-10-03T18:32:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "failure",
            "label": "Unexpected application failure",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "handler",
            "label": "Apply shared error handling contract",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "public",
            "label": "Return minimal generic client response",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "context",
            "label": "Select useful diagnostic context",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "minimize",
            "label": "Exclude secrets and unnecessary personal data",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "protect",
            "label": "Restrict access and apply retention policy",
            "shape": "box",
            "kind": "allowed"
          }
        ],
        "edges": [
          {
            "from": "failure",
            "to": "handler",
            "label": null
          },
          {
            "from": "handler",
            "to": "public",
            "label": "Public response"
          },
          {
            "from": "handler",
            "to": "context",
            "label": "Internal evidence"
          },
          {
            "from": "context",
            "to": "minimize",
            "label": null
          },
          {
            "from": "minimize",
            "to": "protect",
            "label": null
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/error-diagnostic-disclosure-boundary.mmd",
        "graphviz": "diagrams/error-diagnostic-disclosure-boundary.dot",
        "svg": "diagrams/error-diagnostic-disclosure-boundary.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "fallback-requester-authorization",
      "title": "Fallbacks must preserve the original caller's authority",
      "alt_text": "A failure retains the original caller, action and resource. An explicit access denial stops without protected data. A known recoverable operational failure can propose a fallback, but switching execution identity grants no extra caller entitlement. A separate application-policy decision evaluates that fallback for the original caller. Denied or indeterminate decisions stop without protected data. A permitted, scoped fallback returns only caller-permitted data.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Original editorial defensive synthesis of the Instagram embedding disclosure and OWASP authorization guidance. The researcher attributes the disclosure to error handling that retrieved protected content under an elevated service identity, relaying vendor clarification rather than independently published vendor evidence. OWASP supports consistent per-request permissions and safe handling of failed authorization checks. The graph models a safe recovery decision, not Instagram's architecture or a documented patch. An explicit access denial terminates this logical operation; only a known recoverable operational failure may reach fallback review. The original caller, action and resource remain the policy context, even if execution identity changes. Denied or indeterminate fallback authorization stops without protected data. Assumes the same caller and logical operation with an application-defined recovery policy; separately authorized service or background work is excluded. Permission freshness, revocation, distributed consistency and diagnostic minimization are outside this model.",
      "linked_report_ids": [
        "instagram-embedding-privileged-fallback-2023"
      ],
      "linked_resource_ids": [
        "owasp-authorization-cheat-sheet"
      ],
      "evidence_urls": [
        "https://003random.com/posts/meta-bountycon-instagram-writeup/",
        "https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html"
      ],
      "reviewed_at": "2026-10-04T16:02:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "failure",
            "label": "Failure: retain caller, action and resource",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "access-denial",
            "label": "Explicit access denial?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "stop-denial",
            "label": "Stop; no protected data",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "recoverable",
            "label": "Known recoverable operational failure?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "stop-failure",
            "label": "Stop safely; no protected data",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "propose",
            "label": "Propose fallback for the same operation",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "authority",
            "label": "Execution identity grants no extra caller entitlement",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "authorize",
            "label": "Fallback permitted for original caller under policy?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "stop-fallback",
            "label": "Stop; no protected data",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "execute",
            "label": "Execute only permitted scoped fallback",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "response",
            "label": "Return only caller-permitted data",
            "shape": "box",
            "kind": "allowed"
          }
        ],
        "edges": [
          {
            "from": "failure",
            "to": "access-denial",
            "label": null
          },
          {
            "from": "access-denial",
            "to": "stop-denial",
            "label": "Yes"
          },
          {
            "from": "access-denial",
            "to": "recoverable",
            "label": "No"
          },
          {
            "from": "recoverable",
            "to": "stop-failure",
            "label": "No or unknown"
          },
          {
            "from": "recoverable",
            "to": "propose",
            "label": "Yes"
          },
          {
            "from": "propose",
            "to": "authority",
            "label": null
          },
          {
            "from": "authority",
            "to": "authorize",
            "label": null
          },
          {
            "from": "authorize",
            "to": "stop-fallback",
            "label": "Denied or indeterminate"
          },
          {
            "from": "authorize",
            "to": "execute",
            "label": "Permitted"
          },
          {
            "from": "execute",
            "to": "response",
            "label": null
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/fallback-requester-authorization.mmd",
        "graphviz": "diagrams/fallback-requester-authorization.dot",
        "svg": "diagrams/fallback-requester-authorization.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "identity-claim-binding",
      "title": "An identity claim must belong to the user",
      "alt_text": "The identity provider authenticates a subject and binds issued claims to it. The relying application validates the issuer, audience, signature, and ownership binding before mapping to a local account. Failed validation is rejected.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.",
      "linked_report_ids": [
        "apple-sign-in-identity-claim-binding-2020",
        "github-oauth-method-semantics-2019"
      ],
      "linked_resource_ids": [
        "rfc-9700-oauth-security-best-current-practice"
      ],
      "evidence_urls": [
        "https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/",
        "https://blog.teddykatz.com/2019/11/05/github-oauth-bypass.html",
        "https://www.rfc-editor.org/rfc/rfc9700.html"
      ],
      "reviewed_at": "2026-10-02T14:50:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "subject",
            "label": "Authenticated subject",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "claims",
            "label": "Issue claims bound to that subject",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "validate",
            "label": "Valid issuer, audience, signature and subject binding?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "account",
            "label": "Map to the authorized local account",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "reject",
            "label": "Reject inconsistent identity claims",
            "shape": "box",
            "kind": "denied"
          }
        ],
        "edges": [
          {
            "from": "subject",
            "to": "claims",
            "label": null
          },
          {
            "from": "claims",
            "to": "validate",
            "label": null
          },
          {
            "from": "validate",
            "to": "account",
            "label": "Yes"
          },
          {
            "from": "validate",
            "to": "reject",
            "label": "No"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/identity-claim-binding.mmd",
        "graphviz": "diagrams/identity-claim-binding.dot",
        "svg": "diagrams/identity-claim-binding.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "parsing-safety-action-authority",
      "title": "Parsing safety and action authority",
      "alt_text": "Untrusted input is parsed with memory safety and limited privileges. A bounded typed result still requires an independent meaning and authorization check before any scoped operation; failed checks reject the request.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.",
      "linked_report_ids": [
        "google-chrome-v8-type-consistency-2025",
        "redis-lua-object-lifetime-isolation-2025"
      ],
      "linked_resource_ids": [
        "chromium-rule-of-two-input-isolation"
      ],
      "evidence_urls": [
        "https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/rule-of-2.md",
        "https://securitylab.github.com/advisories/GHSL-2025-114_Chromium/",
        "https://github.com/redis/redis/security/advisories/GHSA-4789-qfc9-5f9q"
      ],
      "reviewed_at": "2026-10-02T17:52:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "input",
            "label": "Untrusted input",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "parse",
            "label": "Memory-safe parsing with limited privileges",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "result",
            "label": "Bounded typed result; still untrusted",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "validate",
            "label": "Meaning and action authority valid?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "deny",
            "label": "Reject; preserve protected state",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "allow",
            "label": "Perform only the approved operation",
            "shape": "box",
            "kind": "allowed"
          }
        ],
        "edges": [
          {
            "from": "input",
            "to": "parse",
            "label": null
          },
          {
            "from": "parse",
            "to": "result",
            "label": null
          },
          {
            "from": "result",
            "to": "validate",
            "label": null
          },
          {
            "from": "validate",
            "to": "deny",
            "label": "No"
          },
          {
            "from": "validate",
            "to": "allow",
            "label": "Yes"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/parsing-safety-action-authority.mmd",
        "graphviz": "diagrams/parsing-safety-action-authority.dot",
        "svg": "diagrams/parsing-safety-action-authority.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "server-client-data-consumer-boundaries",
      "title": "Server disclosure and browser interpretation",
      "alt_text": "A request enters a server-side caller, resource and operation authorization decision. Denial returns no protected data. Approval proceeds to explicit field selection before serialization. Only permitted, necessary fields cross into client-visible data. A separate consumer-context handling step keeps content, including generated text, from acquiring executable meaning before display. Browser rendering never supplies server authorization.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model: assumes an application with server-side privileged data and a browser consumer. Next.js guidance supports server authorization and minimal client-visible contracts; OWASP LLM05 supports treating generated text as untrusted at each consumer. The linked HackerOne Rails case illustrates why serialization needs an explicit disclosure boundary; it is not evidence of Next.js or an LLM integration. The arrows show defensive responsibilities, not a framework execution trace. Context-aware encoding or sanitization belongs where the output context is known, including server rendering; the lower steps do not imply exclusively client-side execution. Rendering safety cannot replace permission checks, and authorized disclosure does not make content safe to interpret.",
      "linked_report_ids": [
        "hackerone-report-json-serialization-data-exposure-2025"
      ],
      "linked_resource_ids": [
        "nextjs-server-client-data-security",
        "owasp-llm-output-consumer-trust"
      ],
      "evidence_urls": [
        "https://nextjs.org/docs/app/guides/data-security",
        "https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/",
        "https://www.hackerone.com/blog/hai-insight-agent-case-study"
      ],
      "reviewed_at": "2026-10-03T05:59:11Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "request",
            "label": "Request; UI visibility grants no authority",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "authorize",
            "label": "Server: caller, resource and operation authorized?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "deny",
            "label": "Deny access; disclose no protected data",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "select",
            "label": "Server: select only permitted, needed fields",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "visible",
            "label": "Disclosure boundary: serialized data is client-visible",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "context",
            "label": "Consumer context: encode or sanitize untrusted content",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "display",
            "label": "Display as intended; no new authority",
            "shape": "box",
            "kind": "allowed"
          }
        ],
        "edges": [
          {
            "from": "request",
            "to": "authorize",
            "label": null
          },
          {
            "from": "authorize",
            "to": "deny",
            "label": "No"
          },
          {
            "from": "authorize",
            "to": "select",
            "label": "Yes"
          },
          {
            "from": "select",
            "to": "visible",
            "label": "Minimal contract"
          },
          {
            "from": "visible",
            "to": "context",
            "label": "Including generated text"
          },
          {
            "from": "context",
            "to": "display",
            "label": "Separate rendering control"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/server-client-data-consumer-boundaries.mmd",
        "graphviz": "diagrams/server-client-data-consumer-boundaries.dot",
        "svg": "diagrams/server-client-data-consumer-boundaries.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Mermaid and DOT are generated from this canonical node/edge graph. Graphviz renders the SVG; no Mermaid engine is executed.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "server-request-destination-policy",
      "title": "Layer server-request destination controls",
      "alt_text": "A requested destination passes consistent parsing, application policy and independent network egress checks. Invalid input or either policy failure is rejected. Only an approved destination is requested.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Original conceptual defense-in-depth model linked to the historical Shopify Exchange case and OWASP guidance. It is not a vendor architecture diagram. Policy must fit the service’s destination requirements.",
      "linked_report_ids": [
        "shopify-exchange-request-isolation-2019"
      ],
      "linked_resource_ids": [
        "owasp-server-request-destination-boundaries"
      ],
      "evidence_urls": [
        "https://shopify.engineering/one-million-dollars-in-bug-bounties",
        "https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html"
      ],
      "reviewed_at": "2026-10-02T16:29:00Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "input",
            "label": "Requested destination",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "parse",
            "label": "Consistent parsing and validation",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "policy",
            "label": "Destination permitted by application policy?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "network",
            "label": "Independent egress policy permits access?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "allow",
            "label": "Request only the approved destination",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "deny",
            "label": "Reject the request",
            "shape": "box",
            "kind": "denied"
          }
        ],
        "edges": [
          {
            "from": "input",
            "to": "parse",
            "label": null
          },
          {
            "from": "parse",
            "to": "policy",
            "label": "Valid"
          },
          {
            "from": "parse",
            "to": "deny",
            "label": "Invalid or ambiguous"
          },
          {
            "from": "policy",
            "to": "network",
            "label": "Yes"
          },
          {
            "from": "policy",
            "to": "deny",
            "label": "No"
          },
          {
            "from": "network",
            "to": "allow",
            "label": "Yes"
          },
          {
            "from": "network",
            "to": "deny",
            "label": "No"
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/server-request-destination-policy.mmd",
        "graphviz": "diagrams/server-request-destination-policy.dot",
        "svg": "diagrams/server-request-destination-policy.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats share the canonical graph; Graphviz renders the SVG.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    },
    {
      "schema_version": "1.0.0",
      "id": "workload-identity-tenant-scope",
      "title": "Keep workload authority tenant-scoped",
      "alt_text": "A verified workload identity and a requested operation enter an independent authorization decision. Policy checks the role, action, resource and tenant together. Only the approved resource scope is allowed; other requests are denied. Both decisions produce an audit record.",
      "diagram_type": "defensive_data_flow",
      "interpretation": "Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.",
      "linked_report_ids": [
        "meta-service-identity-secrets-trust-boundary-2026",
        "google-actifio-driver-service-identity-isolation-2025"
      ],
      "linked_resource_ids": [
        "aws-iam-machine-identity-best-practices"
      ],
      "evidence_urls": [
        "https://sectricity.com/blog/misconfigured-grafana-507-private-meta-repos/",
        "https://stazot.com/?article=dataprep-actifio-jar-swapping-rce",
        "https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html"
      ],
      "reviewed_at": "2026-10-02T15:41:13Z",
      "source_graph": {
        "direction": "TB",
        "nodes": [
          {
            "id": "identity",
            "label": "Verified workload identity and tenant context",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "request",
            "label": "Requested action and resource",
            "shape": "box",
            "kind": "data"
          },
          {
            "id": "policy",
            "label": "Do role, action, resource and tenant match policy?",
            "shape": "diamond",
            "kind": "decision"
          },
          {
            "id": "allow",
            "label": "Allow only the approved resource scope",
            "shape": "box",
            "kind": "allowed"
          },
          {
            "id": "deny",
            "label": "Deny access",
            "shape": "box",
            "kind": "denied"
          },
          {
            "id": "audit",
            "label": "Record the authorization decision",
            "shape": "box",
            "kind": "data"
          }
        ],
        "edges": [
          {
            "from": "identity",
            "to": "policy",
            "label": "Verified context"
          },
          {
            "from": "request",
            "to": "policy",
            "label": "Operation"
          },
          {
            "from": "policy",
            "to": "allow",
            "label": "Yes"
          },
          {
            "from": "policy",
            "to": "deny",
            "label": "No"
          },
          {
            "from": "allow",
            "to": "audit",
            "label": null
          },
          {
            "from": "deny",
            "to": "audit",
            "label": null
          }
        ]
      },
      "files": {
        "mermaid": "diagrams/workload-identity-tenant-scope.mmd",
        "graphviz": "diagrams/workload-identity-tenant-scope.dot",
        "svg": "diagrams/workload-identity-tenant-scope.svg"
      },
      "rendering": {
        "renderer": "Graphviz dot 2.42.4",
        "mermaid_engine_executed": false,
        "equivalence_basis": "Both source formats are generated from the same node/edge graph; SVG is rendered from Graphviz, not through a Mermaid engine.",
        "visual_qa": "passed"
      },
      "content_scope": "conceptual_defensive_model"
    }
  ],
  "asset_note": "Diagram asset paths are relative to the repository. SVGs are generated by Graphviz from the same canonical node/edge graph as the Mermaid sources; a Mermaid engine was not executed."
}
