How to use this reference
Editorial lesson: authority-changing metadata needs its own permission check; visibility alone must not authorize membership changes. The advisory identifies versions 3.0.0–3.3.1 as affected and 3.4 as fixed. Release notes date 3.4 to August 5, before disclosure on August 11.
Before reading
- Basic server-side identity and authorization concepts
Context and limits
- Requires an authenticated reviewer or program-committee member and existing submission visibility; this is not an unauthenticated access claim.
- The maintainer reports an action-log review finding no exploitation on its hosted service. That statement does not establish absence of incidents in other deployments. The advisory reports capability and consequences, without a separate production-incident narrative.
- kohler published the advisory; discovery is credited to an internal audit without a named individual reporter. The original report date is unknown.
- This review did not independently verify the patch implementation or deployed state. Upgrade evidence does not establish reversal of any prior unauthorized authorship changes. Learning prerequisites are editorial.
Sources and provenance
- Escalation to author access by reviewers HotCRP · reviewed 2026-10-03
- HotCRP release notes: version 3.4 HotCRP · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.