CVE-2026-43881 fix d9cdc7024 patched users.json.php only. The same anti-pattern survives at master HEAD in:
objects/mention.json.php:17 $ignoreAdmin = true;
objects/mention.json.php:18 $users = User::getAllUsers($ignoreAdmin,
['name', 'email', 'user', 'channelName'], 'a');
No User::loginCheck(), no admin gate. Only entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10.
{
"github_reviewed_at": "2026-05-18T13:30:05Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-204",
"CWE-285"
],
"nvd_published_at": "2026-05-29T14:16:31Z",
"github_reviewed": true
}