GHSA-q3f8-qfx4-gq35HighCVSS 7.3

Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and...

Published
February 19, 2026
Last Modified
June 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection.This issue affects Envanty: before 1.0.6.  

NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be remediated through reporter information and testing.

🔗 References (4)