While working on perforator project, I scanned the dependency manifest and found that it uses a vulnerable version of github.com/openfga/openfga. The scan revealed an issue where the unauthenticated playground endpoint can expose the preshared API key in its HTML response, potentially allowing unauthorized access if the endpoint is publicly accessible.
CVE Report
CVE Link
While working on perforator project, I scanned the dependency manifest and found that it uses a vulnerable version of
github.com/openfga/openfga. The scan revealed an issue where the unauthenticated playground endpoint can expose the preshared API key in its HTML response, potentially allowing unauthorized access if the endpoint is publicly accessible.CVE Report
CVE Link