codefloe.com/crowci/crow/v6
Activity
- Latest release
- 3d ago
- Total releases
- 11
- Cadence
- ~4 days
- Last 12 months
- 11
Details
- First release
- Jul 09, 2026
| Version | Released | |
|---|---|---|
v6.8.1
patch
|
v6.8.1
patch
Dependencies (73)
+ 65 more |
|
v6.8.0
minor
|
v6.8.0
minor
Dependencies (73)
+ 65 more |
|
v6.7.0
minor
|
v6.7.0
minor
Dependencies (74)
+ 66 more |
|
v6.6.0
minor
|
v6.6.0
minor
Dependencies (74)
+ 66 more |
|
v6.5.0
minor
|
v6.5.0
minor
Dependencies (74)
+ 66 more |
|
v6.4.0
minor
|
v6.4.0
minor
Dependencies (74)
+ 66 more |
|
v6.3.0
minor
1 CVE
GO-2026-6216
Aug 18, 2026
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6 In codefloe.com/crowci/crow/v6 before 6.4.0, user account lookup during forge login is not scoped to the authenticating forge. An account on one forge matches an existing user on another forge via forge remote ID collision or username collision. On instances with multiple configured forges, an attacker can take over arbitrary Crow accounts by registering matching credentials on any connected forge. Fixed in
6.4.0
References Updated Aug 18, 2026 · Source: OSV.dev |
v6.3.0
minor
Dependencies (74)
+ 66 more |
|
v6.2.0
minor
1 CVE
GO-2026-6216
Aug 18, 2026
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6 In codefloe.com/crowci/crow/v6 before 6.4.0, user account lookup during forge login is not scoped to the authenticating forge. An account on one forge matches an existing user on another forge via forge remote ID collision or username collision. On instances with multiple configured forges, an attacker can take over arbitrary Crow accounts by registering matching credentials on any connected forge. Fixed in
6.4.0
References Updated Aug 18, 2026 · Source: OSV.dev |
v6.2.0
minor
Dependencies (74)
+ 66 more |
|
v6.1.0
minor
1 CVE
GO-2026-6216
Aug 18, 2026
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6 In codefloe.com/crowci/crow/v6 before 6.4.0, user account lookup during forge login is not scoped to the authenticating forge. An account on one forge matches an existing user on another forge via forge remote ID collision or username collision. On instances with multiple configured forges, an attacker can take over arbitrary Crow accounts by registering matching credentials on any connected forge. Fixed in
6.4.0
References Updated Aug 18, 2026 · Source: OSV.dev |
v6.1.0
minor
Dependencies (74)
+ 66 more |
|
v6.0.2
patch
1 CVE
GO-2026-6216
Aug 18, 2026
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6 In codefloe.com/crowci/crow/v6 before 6.4.0, user account lookup during forge login is not scoped to the authenticating forge. An account on one forge matches an existing user on another forge via forge remote ID collision or username collision. On instances with multiple configured forges, an attacker can take over arbitrary Crow accounts by registering matching credentials on any connected forge. Fixed in
6.4.0
References Updated Aug 18, 2026 · Source: OSV.dev |
v6.0.2
patch
Dependencies (74)
+ 66 more |
|
v6.0.1
initial
1 CVE
GO-2026-6216
Aug 18, 2026
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6 In codefloe.com/crowci/crow/v6 before 6.4.0, user account lookup during forge login is not scoped to the authenticating forge. An account on one forge matches an existing user on another forge via forge remote ID collision or username collision. On instances with multiple configured forges, an attacker can take over arbitrary Crow accounts by registering matching credentials on any connected forge. Fixed in
6.4.0
References Updated Aug 18, 2026 · Source: OSV.dev |
v6.0.1
initial
Dependencies (74)
+ 66 more |