# sonatype-2026-005067

github.com/OpenListTeam/OpenList/v4 - Exposure of Sensitive Information to an Unauthorized Actor

Published Jul 25, 2026

[Advisory · GHSA-p6ph-3jx2-3337](https://github.com/advisories/GHSA-p6ph-3jx2-3337)

## CVSS Score
Medium 4.3

## Security Details

### Components Impacted

Sonatype Research

### sonatype-2026-005067 Security Details

**CVE ID** sonatype-2026-005067  
**CWE** N/A  
**CVE Description** github.com/OpenListTeam/OpenList/v4 - Exposure of Sensitive Information to an Unauthorized Actor  
**Published** Jul 25, 2026  
**CVSS Score & Severity** 4.3 Medium  
**CVSS Vector** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N  
**EPSS Score** 0%  
  
## Malware

malware

## KEV Status

Not in KEV Catalog: No known exploits

## Affected Ecosystems

affected

## Source

Sonatype

## References

[GitHub · Advisory · GHSA-p6ph-3jx2-3337](https://github.com/advisories/GHSA-p6ph-3jx2-3337 "https://github.com/advisories/GHSA-p6ph-3jx2-3337")
