CVE-2026-70617
Spacebar Server Missing Authorization via Group DM Recipient Endpoint
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent.
| CWE | CWE-862 |
| Vendor | spacebar server |
| Product | spacebar server |
| Published | Aug 5, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for spacebar server spacebar server
Be the first to know when new high vulnerabilities affecting spacebar server spacebar server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Spacebar Server / Spacebar Server
0 โค dcfd91035e3da42abf5f32d8d86a35219225b3d4
References
github.com: https://github.com/spacebarchat/server/security/advisories/GHSA-g38j-78fh-jm74 github.com: https://github.com/spacebarchat/server/commit/dcfd91035e3da42abf5f32d8d86a35219225b3d4 vulncheck.com: https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-group-dm-recipient-endpoint
Credits
George Chen