Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.
References
Configurations
No configuration.
History
20 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/lissy93/dashy/security/advisories/GHSA-vjj9-fmvr-6h3p - |
15 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 19:17
Updated : 2026-07-20 16:17
NVD link : CVE-2026-46485
Mitre link : CVE-2026-46485
CVE.ORG link : CVE-2026-46485
JSON object : View
Products Affected
No product.
