blob: 5b53d036f11118ce16259790403af16c74880b27 [file]
id: GO-2026-4892
modules:
- module: github.com/fleetdm/fleet/v4
versions:
- fixed: 4.81.1
vulnerable_at: 4.81.0
summary: |-
A Fleet team maintainer can transfer hosts from any team via missing source team
authorization in github.com/fleetdm/fleet
cves:
- CVE-2026-29180
ghsas:
- GHSA-m2h6-4xpq-qw3m
references:
- advisory: https://github.com/fleetdm/fleet/security/advisories/GHSA-m2h6-4xpq-qw3m
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-29180
- web: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.81.1
notes:
- fix: 'github.com/fleetdm/fleet/v2: could not add vulnerable_at: module github.com/fleetdm/fleet/v2 not known to proxy'
- fix: 'github.com/fleetdm/fleet/v3: could not add vulnerable_at: module github.com/fleetdm/fleet/v3 not known to proxy'
source:
id: GHSA-m2h6-4xpq-qw3m
created: 2026-03-31T13:05:25.242102-04:00
review_status: UNREVIEWED