Security: mayswind/ezbookkeeping
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
API Token → NORMAL Session Token Escalation via tokens/refresh.jsonGHSA-wq25-mpcf-2mfc published
Sep 25, 2026 by mayswindHigh -
TOTP Replay Attack - Same Code Accepted Twice Within Valid Window (RFC 6238 Violation)GHSA-p6qr-48g6-97q3 published
Sep 16, 2026 by mayswindHigh -
Source-IP allowlist (MCP & API token) is bypassable via a spoofed `X-Forwarded-For` headerGHSA-wchh-mrv2-5h4q published
Jul 19, 2026 by mayswindHigh
Learn more about advisories related to mayswind/ezbookkeeping in the GitHub Advisory Database