VulnSea

apitable vulnerabilities

CVEs whose affected-version data names the apitable package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-86120Medium· 4.3
2w ago

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can …

▾ Sunlitapitable · apitableEPSS 0.21%via NVD
CVE-2026-84485High· 7.5
3w ago

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endp…

▾ Twilightapitable · apitableEPSS 0.35%via NVD
CVE-2026-80208High· 8.2
4w ago

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is val…

▾ Twilightapitable · apitableEPSS 0.31%via NVD
CVE-2026-80207Medium· 5.3PoC
4w ago

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gatewa…

▾ Twilightapitable · apitableEPSS 0.29%via NVD
apitable vulnerabilities (CVEs) · VulnSea