Guohongze Adminset Delivery Deployment Endpoint Authorization Bypass Vulnerability

Vulnerability

An authorization bypass vulnerability has been identified in the Guohongze Adminset application, specifically in versions up to 0.61. The issue resides in the delivery deployment endpoint, where the 'project_id' argument is manipulated, allowing users to initiate deployments for projects they do not have permission to access. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows low-privileged users to bypass project-level authorization, enabling unauthorized deployments that could disrupt services or incorrectly roll out code.

Reproduction

To reproduce this vulnerability, create a user with limited permissions assigned to a specific project. This user can then access the delivery deployment URL and, by supplying the 'project_id' of a different project, initiate a deployment for that project without authorization.

Remediation

It is recommended to implement checks that verify a user's permission for a specific project before allowing deployments, ensuring that the same project membership constraints used in the delivery list are applied.

Added: Jul 19, 2026, 6:24 AM
Updated: Jul 19, 2026, 6:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.6
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.