GHSA-62ch-j6x7-722j
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
Quick fix
GHSA-62ch-j6x7-722j — opensource-workshop/connect-cms: upgrade to the fixed version with the command below.
composer require opensource-workshop/connect-cms:^1.41.1Details
# Security Advisory — Page Content Retrieval (Improper Authorization)
## Summary
An improper authorization issue in the page content retrieval feature may allow retrieval of non-public information.
## Affected Versions
- 1.x series: <= 1.41.0 - 2.x series: <= 2.41.0
## Patched Versions
- 1.41.1 - 2.41.1
## Description
In part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version.
## Solution
Update to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later.
## Credits
OpenSource WorkShop thanks **Sho Odagiri** (小田切 祥) of **GMO Cybersecurity by Ierae, Inc.** for reporting this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.41.1composer require opensource-workshop/connect-cms:^1.41.12.0.0Fixed in: 2.41.1composer require opensource-workshop/connect-cms:^2.41.1References
- https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-62ch-j6x7-722j[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-32299[ADVISORY]
- https://github.com/opensource-workshop/connect-cms[PACKAGE]
- https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1[WEB]
- https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1[WEB]