CyberRota Analysis
AI-GeneratedAuthenticated users lacking repository read permissions can exploit specific conditions to access sensitive package metadata. This vulnerability could lead to unauthorized information disclosure, potentially compromising the integrity of the repository. Organizations using affected products should prioritize remediation to safeguard sensitive data from unauthorized access.
CVE
CVE-2026-70547
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
Original NVD Description
An authenticated user without repository read permission may access package metadata under specific conditions.