CVE-2026-53536

Source
https://cve.org/CVERecord?id=CVE-2026-53536
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53536.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53536
Aliases
  • GHSA-9723-fmff-mc24
Published
2026-07-16T18:48:30.875Z
Modified
2026-07-19T03:30:51.707796587Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Activepieces: Cross-tenant file download via missing JWT audience check on step-files signed URL
Details

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined with a missing null-check on the decoded fileId, this allowed any caller holding any valid Activepieces JWT (including a freshly created user's own access token) to receive a step-file belonging to another tenant. The file returned was whatever PostgreSQL happened to scan first for type = FLOWSTEPFILE, varying over time as the database changed, so an authenticated user could obtain step-file attachments belonging to other tenants on the same instance; the attacker could not target a specific victim or file, and the access was read-only with no integrity or availability impact. This issue is fixed in version 0.83.0.

Database specific
{
    "cwe_ids": [
        "CWE-345",
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53536.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/activepieces/activepieces

Affected ranges

Type
GIT
Repo
https://github.com/activepieces/activepieces
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.83.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1.3
0.15.0
0.15.0-rc.2
0.15.0-rc.3
0.15.0-rc.4
0.15.0-rc.5
0.15.0-rc.6
0.15.0-rc.7
0.15.0-rc.8
0.16.0
0.16.0-rc.1
0.16.0-rc.2
0.16.0-rc.3
0.17.0
0.18.0
0.18.0-rc.1
0.18.1
0.18.2
0.19.0
0.19.0-rc.1
0.19.0-rc.2
0.19.0-rc.3
0.19.0-rc.4
0.2.0
0.2.5
0.20.0
0.20.0-rc.2
0.20.0-rc.3
0.20.0-rc.4
0.20.1
0.20.2
0.20.3
0.21.0
0.21.0-rc.1
0.21.0-rc.2
0.21.0-rc.4
0.22.0-rc.1
0.22.0-rc.3
0.22.0-rc.4
0.23.0
0.23.0-rc.1
0.23.0-rc.2
0.24.0
0.24.1
0.25.0
0.25.1
0.26.0
0.26.0-rc.1
0.26.0-rc.2
0.26.0-rc.3
0.26.1
0.27.0
0.27.0-rc.1
0.27.0-rc.2
0.27.0-rc.3
0.27.0-rc.4
0.27.0-rc.5
0.27.0-rc.6
0.27.0-rc.7
0.27.0-rc.8
0.28.0
0.28.0-rc.1
0.29.0
0.29.0-rc.1
0.29.0-rc.3
0.29.1
0.3.15
0.3.3
0.3.5
0.3.6
0.30.0-rc.1
0.30.0-rc.3
0.30.0-rc.4
0.30.0-rc.5
0.30.0-rc.6
0.30.0-rc.7
0.30.0-rc.8
0.34.11
0.35.0
0.35.1
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.37.0
0.37.1
0.37.2
0.37.3
0.37.4
0.37.5
0.37.6
0.38.0
0.38.1
0.38.2
0.38.3
0.38.6
0.39.0
0.39.1
0.39.2
0.39.3
0.39.4
0.39.5
0.39.6
0.39.7
0.39.9
0.4.0
0.41.0
0.41.0-rc.1
0.42.0
0.42.0-rc.1
0.45.0
0.45.1
0.46.0
0.46.3
0.46.5
0.46.6
0.46.7
0.47.2
0.47.4
0.48.0
0.48.1
0.48.2
0.48.3
0.48.6
0.48.7
0.49.0
0.49.0-rc.0
0.50.0
0.50.1
0.50.10
0.50.11
0.50.12
0.50.2
0.50.3
0.50.4
0.50.5
0.50.7
0.50.8
0.50.9
0.53.0
0.53.1
0.54.0
0.56.0
0.57.0
0.57.1
0.59.0
0.60.0
0.60.2
0.63.0
0.64.0
0.64.0-rc.0
0.64.1
0.64.2
0.65.0
0.66.0
0.66.1
0.66.2
0.66.3
0.66.4
0.66.5
0.66.6
0.66.7
0.67.0
0.67.1
0.67.2
0.67.3
0.67.4
0.67.5
0.67.6
0.68.0
0.68.1
0.68.2
0.68.3
0.69.0
0.7.0
0.70.0
0.70.1
0.70.2
0.70.3
0.70.4
0.70.5
0.70.6
0.70.7
0.70.8
0.71.0
0.71.1
0.71.3
0.71.4
0.72.0
0.72.1
0.72.2
0.72.3
0.73.0
0.74.0
0.74.3
0.74.4
0.75.0
0.76.0
0.76.2
0.77.1
0.77.2
0.77.3
0.77.4
0.77.5
0.77.6
0.78.0
0.78.1
0.78.2
0.79.0
0.80.0
0.80.0-rc
0.80.1
0.82.0
0.82.0-rc.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53536.json"