Security: profullstack/qryptchat-web
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Global read of the users table exposes all users' phone numbers to any authenticated accountGHSA-7w99-6w89-2926 published
Aug 16, 2026 by Noir0x63High -
[HIGH] Platform-wide Message Deletion and Weak JWT Session Validation in Cleanup EndpointsGHSA-2wqx-qppx-4rgf published
Aug 14, 2026 by Noir0x63High -
[HIGH] Unauthenticated User Identity Spoofing and Phone Number Overwrite via sync_user_with_authGHSA-xgqr-8f4j-mc7j published
Aug 14, 2026 by Noir0x63High -
[HIGH] Unauthenticated Call History Surveillance and Active Call IDOR via SECURITY DEFINER RPCsGHSA-37x4-hjgx-9mw8 published
Aug 14, 2026 by Noir0x63High -
[HIGH] Unsalted SHA-256 Backup PIN Derivation and Horizontal User Hash Exposure via RLSGHSA-jpfm-vrpc-p6rr published
Aug 14, 2026 by Noir0x63High -
[CRITICAL] RLS Policy Drift Exposing User Profiles and Encrypted Messages in Fresh DeploymentsGHSA-67rc-3r93-2xw5 published
Aug 14, 2026 by Noir0x63Critical -
[CRITICAL] Unauthenticated Remote Data Destruction via SECURITY DEFINER RPC delete_encrypted_data_onlyGHSA-6c47-c2gr-2gp8 published
Aug 14, 2026 by Noir0x63Critical
Learn more about advisories related to profullstack/qryptchat-web in the GitHub Advisory Database