Security: msgbyte/tianji
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
SQL Injection via unvalidated timezone header — ClickHouse analytics code path (distinct from patched GHSA-v9jm-vvrj-53c4)GHSA-954m-4cfc-rr2x published
Aug 30, 2026 by moonrailgunHigh -
Cross-workspace read of any tenant external database via unscoped warehouse.query.execute (BOLA)GHSA-2hh4-qwxf-r72h published
Aug 30, 2026 by moonrailgunHigh -
Remote Code Execution via lodash template evaluate pattern in survey feed templatesGHSA-5grg-j3cr-3hpm published
Jun 18, 2026 by moonrailgunCritical -
SQL Injection via unsanitized timezone parameter in analytics queriesGHSA-v9jm-vvrj-53c4 published
Jun 18, 2026 by moonrailgunHigh
Learn more about advisories related to msgbyte/tianji in the GitHub Advisory Database