GHSA-p23g-mvhj-jh3j: GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
Summary
GeoLens had multiple authorization bypass vulnerabilities where the system only checked permission for the resource named in the URL but failed to re-check permission for a second dataset accessed through relationships or references, allowing attackers to read private dataset metadata, table rows, vector tiles (map feature data), and raster pixels (image pixel values). Some vulnerabilities required no login at all, while others only needed a default user account. All issues are fixed in version 1.2.3.
Solution / Mitigation
Upgrade to version 1.2.3. According to the source: 'All issues are fixed in 1.2.3. There is no complete configuration workaround — upgrading is the only full remediation.' All versions prior to 1.2.3 are affected (including 1.0.0, 1.2.0, and 1.2.2).
Vulnerability Details
EPSS: 0.0%
Yes
August 18, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-p23g-mvhj-jh3j
First tracked: August 18, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 75%