CVE-2026-63647

Source
https://cve.org/CVERecord?id=CVE-2026-63647
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63647.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63647
Aliases
  • GHSA-9qg8-cm35-xqp4
Published
2026-09-18T19:53:51Z
Modified
2026-09-20T14:13:50Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`
Details

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an identity from an authenticated principal. An unauthenticated caller can use /sse/subscribe to read another user's workflow events, approval requests, mentions, and alerts, use /sse/broadcast to inject SYSTEM_HEARTBEAT messages into another user's stream, or use /sse/close to terminate another user's channel. This vulnerability is fixed in 1.7.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-306",
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63647.json"
}
References

Affected packages

Git / github.com/1panel-dev/cordyscrm

Affected ranges

Type
GIT
Repo
https://github.com/1panel-dev/cordyscrm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.7.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.4.0
v1.4.1
v1.5.0
v1.5.1
v1.5.2
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63647.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "162092298023779250647569139820112961626",
            "length": 1468
        },
        "id": "CVE-2026-63647-18ab98b7",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java",
            "function": "translateConditionValue"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "2169227249485403836733026536955779330",
            "length": 774
        },
        "id": "CVE-2026-63647-42c635ef",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseService.java",
            "function": "addClient"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "13647614030539891900209547784948376122",
                "177302053198085789546864309713875756748",
                "266894628680622095877158504816806573176",
                "232440938878962504416225006544188930118",
                "178703801923108454215267151507721668507",
                "192191908576210986075135055054423048148",
                "36104370984581612745691606069775050486",
                "226463385340970811546259663739999254662",
                "66629506080729363135913074973083795406"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63647-4ea6879e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseController.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "69284159231027381988068726735708236427",
                "153326549275395043884608174236663226870",
                "5675912135259305242487244083456446787",
                "56719794282321096053600032141952913913"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63647-87c055f9",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "217812939056286841266395275268640102149",
                "112649252043734703874402543615723832883",
                "9542532045047258073951761393684157135",
                "28296968785308045174767419136619848648",
                "228433550119071121396002305461679498584",
                "35146771633655077929448576682560713025",
                "319280518914851753663922389570993635345",
                "271364206980095722046413727674352920001",
                "339560178953728291259690786389009651538",
                "300900461281234157190806591390512445806",
                "103703906955608730734220357469991331918",
                "19547618076417822620797207647310498111",
                "63343417572325930389556308272247458458",
                "245965094932134568814809606081854351698",
                "277687008640471514107504531046236159549",
                "62947647734143272223532411887300930590",
                "112719122728509182566157424399589548650",
                "178214851372768858833257926120475849828",
                "30317570930917599866909196851440052374",
                "128353985762766684865884753961420633346",
                "164797241620460892049041186176867166239",
                "16734381131808925585213888148389091397",
                "30889538224285882168071080513375358594",
                "119755695838275159855151270148254098589",
                "937805274976244451436987247581916516",
                "81290013791334087637306511718992775616"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-63647-8af001bd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "215529080361755172337497536441095427735",
            "length": 456
        },
        "id": "CVE-2026-63647-da0a2627",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java",
            "function": "translateConditionFieldName"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "84143096089906834140995583650045534772",
            "length": 211
        },
        "id": "CVE-2026-63647-e375c81f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/6cb81deb53434ae7792673c50312ff91685d7f9d",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/system/notice/sse/SseController.java",
            "function": "broadcast"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "95042265967127000982874536480550717966",
            "length": 875
        },
        "id": "CVE-2026-63647-ec7e36ed",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/1panel-dev/cordyscrm/commit/d166d1b7049888029c13d9a9065fe2caf4800794",
        "target": {
            "file": "backend/crm/src/main/java/cn/cordys/crm/approval/service/ApprovalFlowLogService.java",
            "function": "translateStageValue"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:13:50Z"