Information disclosure in titra - #VU126576
Published: April 20, 2026
titra
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the globalsettings Meteor publication when handling DDP subscription requests. A remote user can subscribe to the publication using a non-admin account to disclose sensitive information.
Exposed data includes configuration fields such as google_secret, openai_apikey, and google_clientid.