Security: rommapp/romm
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Authenticated IDOR in /api/raw/assets/{path} lets any user read other users' assets (saves, states, screenshots, avatars)GHSA-fjfx-pqq5-992r published
Jul 20, 2026 by gantoineModerate -
Unauthenticated Exposure of User Asset Files via Static nginx SymlinkGHSA-mc59-mv52-vvmc published
Jul 20, 2026 by gantoineHigh -
SSRF via DNS Resolution Bypass in `url_manual` FetchGHSA-8x54-qc7x-c8c4 published
Jun 17, 2026 by gantoineHigh -
Unrestricted Upload of File with Dangerous Type and Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in rommGHSA-6g2p-hg42-pfq8 published
Jul 6, 2026 by gantoineHigh -
SSRF Protection Bypass via DNS Rebinding in validate_url_for_http_requestGHSA-8w6h-m97h-67wv published
Jun 17, 2026 by gantoineModerate -
Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) via url_cover, and url_manual fields in ROM and Collection endpointsGHSA-6p56-cp77-w25q published
Jun 17, 2026 by gantoineHigh -
ScreenScraper User Credentials Exposed Via Asset URLsGHSA-3rmg-j6mh-5m76 published
Mar 9, 2026 by gantoineHigh -
Sessions Does Not Invalidated on Password Change or LogoutGHSA-fg2h-rgjw-76r3 published
Jan 9, 2026 by gantoineLow -
Race Condition (TOCTOU) Allows Multiple Account Creation from Single Invitation TokenGHSA-wh3g-54gh-jcvh published
Jan 9, 2026 by gantoineModerate -
Insecure Direct Object Reference (IDOR) Allows Unauthorized Deletion of User CollectionsGHSA-v7c8-f6xc-rv9g published
Dec 3, 2025 by gantoineHigh