vulns.co
/
GKData.io MCP

Outline · 1 min read

Outline: integration authority must end with its owning account

GHSA-33jq-x32c-3ccw describes webhook authority surviving deletion of its creator. Account cleanup omitted webhook subscriptions, while delivery trusted their enabled state. The maintainer-published report describes a local demonstration of document content delivery after the administrator account was deleted.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: revocation must cover durable integrations and every terminal account state, with delivery-time checks as defense in depth. The advisory identifies 1.8.0 as patched. Its proposed cleanup changes are recommendations, not evidence of the implemented patch.

Before reading

  • Basic server-side authorization concepts

Context and limits

  • Requires a webhook previously configured by an administrator, followed by account deletion and a matching document event. The demonstrated deployment used 0.86.0; the maintainer lists versions through 1.7.1 as affected.
  • Continued delivery was demonstrated locally; no production incident, measured duration or customer exposure is established. Persistent exposure is the report’s inference from absent expiry and revalidation.
  • Published June 6, 2026 by tommoor, with dizconnectz credited as reporter. Publication does not establish the release date of 1.8.0. Learning prerequisites are editorial.

Sources and provenance

  1. Webhook subscription persists after creator's account deletion Outline · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software