Collaboration Metadata Exposure in SysReptor Pentest Reporting Platform
CVE-2026-81178
3.5LOW
What is CVE-2026-81178?
SysReptor, a customizable pentest reporting platform, has a vulnerability that allows unauthenticated users holding a public note share link to access project-wide collaborative editing metadata. This occurs because the public share consumer unintentionally joins the same collaboration group as authenticated project members, resulting in the unrestrained forwarding of client information, including usernames, names, and editing events. Even though the content of non-shared notes remains secure and protected, the exposure of metadata could potentially identify project members and reveal live editing activity, which raises privacy concerns. This issue has been addressed and resolved in version 2026.55.
Affected Version(s)
sysreptor < 2026.55
