CyberRota Analysis
AI-GeneratedThe vulnerability in AFFiNE's histories GraphQL field allows authenticated users to bypass Doc.Read permission checks, enabling them to access sensitive document edit histories, including user names, emails, and timestamps. This exposure of restricted content poses a risk to user privacy and data integrity. Organizations using AFFiNE should prioritize addressing this issue to protect their sensitive information from unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUIDs to access full edit histories including user names, emails, and timestamps of private pages they lack access to.