HIGH 7.5 GitHub

CVE-2026-55178

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

### Summary Multiple GeoLens read/link endpoints authorized only the resource named in the request URL (a map, a VRT, a source dataset, an AI request) and failed to re-authorize a **second, caller-influenced dataset** that the request reached through a relationship, layer reference, mosaic source, or request body. This "authorize the URL resource, read a *different* dataset un-re-authorized" pattern let callers read data from datasets they have no access to. The most severe instances require *

Affected Products

References

Published: 2026-08-18 · Source: GitHub · Feed updated: 2026-08-18
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-18 via GitHub. Affected: npm/@geolens/sdk < 1.2.3, pip/geolens-cli < 1.2.3, pip/geolens < 1.2.3.
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.