blob: 334d37fd61027adb96528b60a2407dc3691b3dcb [file]
id: GO-2026-4822
modules:
- module: github.com/pinchtab/pinchtab
versions:
- introduced: 0.7.8
- fixed: 0.8.4
vulnerable_at: 0.8.3
summary: |-
PinchTab: API Bearer Token Exposed in URL Query Parameter via Server Logs and
Intermediary Systems in github.com/pinchtab/pinchtab
cves:
- CVE-2026-33620
ghsas:
- GHSA-mrqc-3276-74f8
references:
- advisory: https://github.com/pinchtab/pinchtab/security/advisories/GHSA-mrqc-3276-74f8
- web: https://github.com/pinchtab/pinchtab/releases/tag/v0.8.4
source:
id: GHSA-mrqc-3276-74f8
created: 2026-03-26T15:28:33.263737975-04:00
review_status: UNREVIEWED