{"id":"GHSA-xhv3-q4xx-349r","summary":"stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)","details":"### Summary\nOn a multi-tenant stigmem node, a tenant administrator could list, read, and **admit or reject** quarantined facts belonging to **other** tenants. The list/count queries and `_get_quarantined_fact` in `routes/quarantine.py` lacked an `f.tenant_id = identity.tenant_id` predicate, and the garden lookup was not tenant-scoped — reached via the `/v1/quarantine` list and admit/reject endpoints.\n\n### Impact\nCross-tenant confidentiality (reading another tenant's quarantined content) and cross-tenant integrity (moderating — admitting or rejecting — another tenant's facts), gated only by a plain tenant `write` capability rather than a node-level admin authority.\n\n### Affected configurations\nThis is a cross-**tenant** break. It is exploitable **only** on deployments running the opt-in `stigmem-plugin-multi-tenant` (multiple tenants on one node). A default single-tenant node has only `tenant=\"default\"` — there is no second tenant to cross — so it is **not exploitable** on default deployments. The rating is HIGH for the multi-tenant deployments the plugin exists to isolate.\n\n### Patches\nFixed in `0.9.0a12` (PR #728): `AND f.tenant_id = identity.tenant_id` was added to the list/count queries and `_get_quarantined_fact`; the garden lookup is now tenant-scoped; and any genuinely cross-tenant moderation is gated behind `can_admin_federation()` (node superadmin), not a tenant `write` capability. A tenant-B admin can no longer list, admit, or reject tenant-A's quarantined facts.\n\n### Workarounds\nNone other than upgrading to `0.9.0a12`. Single-tenant deployments are unaffected.","aliases":["CVE-2026-76237"],"modified":"2026-08-20T04:04:12.294857332Z","published":"2026-06-19T21:43:00Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-19T21:43:00Z","nvd_published_at":null,"cwe_ids":["CWE-639","CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-xhv3-q4xx-349r"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/pull/728"},{"type":"PACKAGE","url":"https://github.com/eidetic-labs/stigmem"}],"affected":[{"package":{"name":"stigmem-node","ecosystem":"PyPI","purl":"pkg:pypi/stigmem-node"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0a12"}]}],"versions":["0.9.0a1","0.9.0a10","0.9.0a11","0.9.0a2","0.9.0a3","0.9.0a4","0.9.0a5","0.9.0a6","0.9.0a7","0.9.0a8","0.9.0a9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-xhv3-q4xx-349r/GHSA-xhv3-q4xx-349r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}