garminconnect
Python 3 API wrapper for Garmin Connect to get statistics and set activities
Activity
- Latest release
- 2d ago
- Total releases
- 108
- Cadence
- ~9 days
- Last 12 months
- 24
Reach
- Stars
- 3.0k
Details
- License
- MIT
- First release
- Jan 04, 2020
| Version | Released | |
|---|---|---|
0.3.15
patch
| ||
0.3.14
patch
| ||
0.3.13
patch
| ||
0.3.11
patch
| ||
0.3.10
patch
| ||
0.3.9
patch
| ||
0.3.8
patch
| ||
0.3.7
patch
| ||
0.3.6
patch
| ||
0.3.5
patch
| ||
0.3.4
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.3.3
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.40
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.39
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.38
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.37
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.36
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.35
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.34
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.33
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.31
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.30
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.29
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.28
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.27
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.26
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.25
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.24
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.23
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.22
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.21
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.20
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.19
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.18
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.17
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.16
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.15
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.14
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.13
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.12
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.11
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.10
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.9
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.8
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.7
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.6
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev | ||
0.2.5
patch
1 CVE
CVE-2026-54447
PYSEC-2026-3467
GHSA-wjhr-76vg-2hvc
Jul 23, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
8.4
/ 10
High
Local
Low
Low
None
Changed
High
High
None
Insecure Permission Assignment for Garmin OAuth Token StoreSummary
Details
The serialized payload includes Under
A separate, unprivileged user on the same machine could read the file with a plain ImpactLocal credential theft / privilege escalation on multi-user Linux or macOS hosts running under a permissive umask. The stolen refresh token can be exchanged for fresh access tokens via Garmin's OAuth endpoint, granting ongoing access to the victim's account (health/fitness data, activity history, device management) until the token is revoked. PatchFixed in 0.3.5 (commit
Verified under WorkaroundsIf you cannot upgrade immediately, restrict the token store manually and keep it owner-only:
Remediation
CreditReported by EQSTLab via a private security advisory. garminconnect thanks them for the detailed, responsible disclosure. Affected versions
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
+ 86 more Show less
0.1.21
0.1.22
0.1.23
0.1.24
0.1.25
0.1.26
0.1.27
0.1.28
0.1.29
0.1.3
0.1.30
0.1.31
0.1.32
0.1.33
0.1.34
0.1.35
0.1.36
0.1.37
0.1.38
0.1.39
0.1.4
0.1.40
0.1.41
0.1.42
0.1.43
0.1.44
0.1.45
0.1.46
0.1.47
0.1.48
0.1.49
0.1.5
0.1.50
0.1.51
0.1.52
0.1.53
0.1.54
0.1.55
0.1.6
0.1.7
0.1.8
0.1.9
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.25
0.2.26
0.2.27
0.2.28
0.2.29
0.2.3
0.2.30
0.2.31
0.2.33
0.2.34
0.2.35
0.2.36
0.2.37
0.2.38
0.2.39
0.2.4
0.2.40
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
Fixed in
0.3.5
References
Updated Jul 23, 2026 · Source: OSV.dev |