HIGH 7.5 GitHub
CVE-2026-55178
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
### Summary
Multiple GeoLens read/link endpoints authorized only the resource named in the
request URL (a map, a VRT, a source dataset, an AI request) and failed to
re-authorize a **second, caller-influenced dataset** that the request reached
through a relationship, layer reference, mosaic source, or request body. This
"authorize the URL resource, read a *different* dataset un-re-authorized"
pattern let callers read data from datasets they have no access to.
The most severe instances require *
Affected Products
- npm/@geolens/sdk < 1.2.3
- pip/geolens-cli < 1.2.3
- pip/geolens < 1.2.3
References
- https://github.com/advisories/GHSA-p23g-mvhj-jh3j
- https://github.com/geolens-io/geolens/security/advisories/GHSA-p23g-mvhj-jh3j
- https://github.com/geolens-io/geolens/pull/234
- https://github.com/geolens-io/geolens/pull/235
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-18 via GitHub. Affected: npm/@geolens/sdk < 1.2.3, pip/geolens-cli < 1.2.3, pip/geolens < 1.2.3.
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.