CVE Explorer
CVE-2026-47236
Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members API. The Jetstream web team page authorizes access with only belongsToTeam() and then loads and serializes all pending invitation emails as well as members into Inertia props. Any employee who belongs to the organization can read pending invitation email addresses and members through the serialised iner
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"solidtime","vendor":"solidtime-io","versions":[{"status":"affected","version":"< 0.12.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e4718acb79d75c115a3a817fd3a0020d3e77383829a037355683f304d81f80b1 · sha256:9a2a48053c9404e9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e4718acb79d75c115a3a817fd3a0020d3e77383829a037355683f304d81f80b1 · sha256:9a2a48053c9404e9… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e4718acb79d75c115a3a817fd3a0020d3e77383829a037355683f304d81f80b1 · sha256:9a2a48053c9404e9… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/solidtime-io/solidtime/releases/tag/v0.12.2","tags":["x_refsource_MISC"],"url":"https://github.com/solidtime-io/solidtime/releases/tag/v0.12.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e4718acb79d75c115a3a817fd3a0020d3e77383829a037355683f304d81f80b1 · sha256:9a2a48053c9404e9… · /containers/cna/references/1
{"name":"https://github.com/solidtime-io/solidtime/security/advisories/GHSA-33xq-wf67-c7vh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/solidtime-io/solidtime/security/advisories/GHSA-33xq-wf67-c7vh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e4718acb79d75c115a3a817fd3a0020d3e77383829a037355683f304d81f80b1 · sha256:9a2a48053c9404e9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.