Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-59709 2 Ghostfol, Ghostfolio 2 Ghostfolio, Ghostfolio 2026-07-08 4.3 Medium
Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.
CVE-2026-59708 2 Ghostfol, Ghostfolio 2 Ghostfolio, Ghostfolio 2026-07-08 7.5 High
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.