---
id: GHSA-x26h-xmv8-gxf7
title: >-
  stigmem-node: RTBF tombstones are mis-attributed and suppress reads
  tenant-blind (cross-tenant BOLA)
summary: >-
  stigmem-node: RTBF tombstones are mis-attributed and suppress reads
  tenant-blind (cross-tenant BOLA)
severity: high
cwe:
  - CWE-639
vendor: stigmem-node
product: stigmem-node
ecosystem: pip
affected:
  - stigmem-node < 0.9.0a12
patched:
  - stigmem-node 0.9.0a12
published: '2026-06-19'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-x26h-xmv8-gxf7'
references:
  - url: >-
      https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-x26h-xmv8-gxf7
  - url: 'https://github.com/eidetic-labs/stigmem/pull/728'
  - url: 'https://github.com/advisories/GHSA-x26h-xmv8-gxf7'
tags:
  - ghsa
  - pip
ingestedAt: '2026-06-22T13:35:24.238Z'
---

## Overview

### Summary
On a multi-tenant stigmem node, RTBF (right-to-be-forgotten) tombstones were mis-scoped two ways. (1) `issue_tombstone` defaulted the tenant to `"default"` instead of the caller's tenant, so tombstones could be written to the wrong tenant. (2) The read-suppression path — `_get_tombstone_filter` (`routes/facts/common.py`) and the `_tombstone_scope_cache` (`lifecycle/tombstones.py`) — had no `tenant_id` predicate, so tombstone suppression was applied tenant-blind across fact queries and provenance. Reached via `/v1/tombstones` and the fact query/provenance read paths.

### Impact
Cross-tenant integrity of the RTBF mechanism: a tenant's deletion request could be recorded against the wrong tenant, and tombstone suppression could hide — or fail to hide — facts across tenant boundaries, undermining both data-view correctness and RTBF guarantees.

### Affected configurations
This is a cross-**tenant** break. It is exploitable **only** on deployments running the opt-in `stigmem-plugin-multi-tenant` (multiple tenants on one node). A default single-tenant node has only `tenant="default"` — there is no second tenant to cross — so it is **not exploitable** on default deployments. The rating is HIGH for the multi-tenant deployments the plugin exists to isolate.

### Patches
Fixed in `0.9.0a12` (PR #728): `identity.tenant_id` is passed from `issue_tombstone` into `create_tombstone` (no more `"default"` fallback); `AND tenant_id = ?` was added to `_get_tombstone_filter` and `get_tombstone_status`; the suppression cache is re-keyed to include tenant; and all four read call sites thread the caller's tenant. A tenant-B tombstone now suppresses only tenant-B facts and is invisible to tenant-A reads.

### Workarounds
None other than upgrading to `0.9.0a12`. Single-tenant deployments are unaffected.

## Affected packages

- `stigmem-node < 0.9.0a12`

## Remediation

Upgrade to a patched release:

- `stigmem-node 0.9.0a12`
