{"id":"GHSA-x26h-xmv8-gxf7","summary":"stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)","details":"### Summary\nOn a multi-tenant stigmem node, RTBF (right-to-be-forgotten) tombstones were mis-scoped two ways. (1) `issue_tombstone` defaulted the tenant to `\"default\"` instead of the caller's tenant, so tombstones could be written to the wrong tenant. (2) The read-suppression path — `_get_tombstone_filter` (`routes/facts/common.py`) and the `_tombstone_scope_cache` (`lifecycle/tombstones.py`) — had no `tenant_id` predicate, so tombstone suppression was applied tenant-blind across fact queries and provenance. Reached via `/v1/tombstones` and the fact query/provenance read paths.\n\n### Impact\nCross-tenant integrity of the RTBF mechanism: a tenant's deletion request could be recorded against the wrong tenant, and tombstone suppression could hide — or fail to hide — facts across tenant boundaries, undermining both data-view correctness and RTBF guarantees.\n\n### Affected configurations\nThis is a cross-**tenant** break. It is exploitable **only** on deployments running the opt-in `stigmem-plugin-multi-tenant` (multiple tenants on one node). A default single-tenant node has only `tenant=\"default\"` — there is no second tenant to cross — so it is **not exploitable** on default deployments. The rating is HIGH for the multi-tenant deployments the plugin exists to isolate.\n\n### Patches\nFixed in `0.9.0a12` (PR #728): `identity.tenant_id` is passed from `issue_tombstone` into `create_tombstone` (no more `\"default\"` fallback); `AND tenant_id = ?` was added to `_get_tombstone_filter` and `get_tombstone_status`; the suppression cache is re-keyed to include tenant; and all four read call sites thread the caller's tenant. A tenant-B tombstone now suppresses only tenant-B facts and is invisible to tenant-A reads.\n\n### Workarounds\nNone other than upgrading to `0.9.0a12`. Single-tenant deployments are unaffected.","aliases":["CVE-2026-76236"],"modified":"2026-08-20T04:04:12.223694065Z","published":"2026-06-19T21:42:57Z","database_specific":{"cwe_ids":["CWE-639"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-19T21:42:57Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-x26h-xmv8-gxf7"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/pull/728"},{"type":"PACKAGE","url":"https://github.com/eidetic-labs/stigmem"}],"affected":[{"package":{"name":"stigmem-node","ecosystem":"PyPI","purl":"pkg:pypi/stigmem-node"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0a12"}]}],"versions":["0.9.0a1","0.9.0a10","0.9.0a11","0.9.0a2","0.9.0a3","0.9.0a4","0.9.0a5","0.9.0a6","0.9.0a7","0.9.0a8","0.9.0a9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-x26h-xmv8-gxf7/GHSA-x26h-xmv8-gxf7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"}]}