{"id":"GHSA-x5cx-w6p2-mxf2","title":"Wagtail: Improper permission handling when copying snippets","summary":"Wagtail: Improper permission handling when copying snippets","severity":"medium","cvss":6.5,"cwe":["CWE-280"],"vendor":"wagtail","product":"wagtail","ecosystem":"pip","affected":["wagtail < 7.0.9","wagtail >= 7.1, < 7.3.4","wagtail >= 7.4, < 7.4.3","wagtail = 8.0rc1"],"patched":["wagtail 7.0.9","wagtail 7.3.4","wagtail 7.4.3","wagtail 8.0rc2"],"published":"2026-08-20","updated":"2026-08-20","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-x5cx-w6p2-mxf2","references":[{"url":"https://github.com/wagtail/wagtail/security/advisories/GHSA-x5cx-w6p2-mxf2"},{"url":"https://github.com/advisories/GHSA-x5cx-w6p2-mxf2"}],"tags":["ghsa","pip"],"ingestedAt":"2026-08-20T18:59:53.240Z","slug":"GHSA-x5cx-w6p2-mxf2","body":"## Overview\n\n### Impact\nA CMS user with \"add\" permission over a snippet model, but not \"change\" or \"view\" permission, could copy an existing snippet that they do not have access to, allowing them to view its contents.\n\n### Patches\nPatched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.\n\n### Workarounds\nN/A\n\n### Acknowledgements\nMany thanks to tinyb0y for reporting this issue.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Visit Wagtail's [support channels](https://docs.wagtail.org/en/stable/support.html)\n* Email us at [security@wagtail.org](mailto:security@wagtail.org) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).\n\n## Affected packages\n\n- `wagtail < 7.0.9`\n- `wagtail >= 7.1, < 7.3.4`\n- `wagtail >= 7.4, < 7.4.3`\n- `wagtail = 8.0rc1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `wagtail 7.0.9`\n- `wagtail 7.3.4`\n- `wagtail 7.4.3`\n- `wagtail 8.0rc2`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}