Back

MEDIUM

KHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation Automation

Published Apr 29, 2025

Description

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord usernames, were exposed in API responses without proper access controls. This allowed unauthorized users to access sensitive user information by directly calling specific endpoints. This issue has been patched in a later commit on version 1.2.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Apr 29, 2025
Updated Apr 30, 2025
Reserved Apr 24, 2025

CISA Vulnrichment

Updated Apr 30, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Apr 29, 2025
Updated Apr 30, 2025

GitHub

No data