Intel

AIKIDO-2026-11017

@lightdash/common is vulnerable to Improper Authorization

Improper Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

47

Medium Risk

This Affects:

JS@lightdash/common
0.2020.0 - 0.3068.1
Fixed in 0.3069.0
Are you affected? Scan for Free

TL;DR

In versions before 0.3069.0, the scheduler send-now path failed to verify whether the requester could view the underlying chart, dashboard, SQL chart, or app, checking only whether they could manage scheduled deliveries. As a result, an editor with create:ScheduledDeliveries could trigger immediate delivery of content stored in a private space they were not authorized to access, causing unauthorized disclosure to the scheduler’s configured recipients. An attacker could exploit this by locating or reusing the UUID of a scheduler tied to restricted content and invoking the send now action, effectively exfiltrating rendered private data without having direct view permission.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@lightdash/common is vulnerable to Improper Authorization in versions 0.2020.0 - 0.3068.1.

How to fix this

Upgrade the @lightdash/common library to the patch version.