{"data":{"id":"0e472850-7473-4ee2-902a-4141ec159cd2","title":"GHSA-p23g-mvhj-jh3j: GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data","summary":"GeoLens had multiple authorization bypass vulnerabilities where the system only checked permission for the resource named in the URL but failed to re-check permission for a second dataset accessed through relationships or references, allowing attackers to read private dataset metadata, table rows, vector tiles (map feature data), and raster pixels (image pixel values). Some vulnerabilities required no login at all, while others only needed a default user account. All issues are fixed in version 1.2.3.","solution":"Upgrade to version 1.2.3. According to the source: 'All issues are fixed in 1.2.3. There is no complete configuration workaround — upgrading is the only full remediation.' All versions prior to 1.2.3 are affected (including 1.0.0, 1.2.0, and 1.2.2).","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-p23g-mvhj-jh3j","publishedAt":"2026-08-18T18:00:07.000Z","cveId":"CVE-2026-55178","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":["geolens@< 1.2.3 (fixed: 1.2.3)","geolens-cli@< 1.2.3 (fixed: 1.2.3)","@geolens/sdk@< 1.2.3 (fixed: 1.2.3)"],"affectedVendors":[],"affectedVendorsRaw":["GeoLens"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-18T18:00:07.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}