You can find our VDP here: https://free.law/vulnerability-disclosure-policy/
Security: freelawproject/courtlistener
Security
SECURITY.md
-
Any Authenticated User Can Deface/Delete Other Users' Published Tags and Pollute Any User's Tag (Including Private) With Arbitrary DocketsGHSA-4587-9786-r6vp published
Aug 15, 2026 by mlissnerHigh -
Missing Object-Level Authorization Allowed Deleting and Reassigning Other Users' PACER Fetch RequestsGHSA-5f8h-qjq5-6h64 published
Aug 15, 2026 by mlissnerModerate -
Unvalidated RECAP PDF Uploads Allow Any Uploader to Silently Overwrite Public Court Document ContentGHSA-6m5w-9h99-2c84 published
Aug 19, 2026 by mlissnerModerate -
Donor Stub Account Takeover via Brute-Forceable Email Confirmation TokenGHSA-638g-xf9h-6qcg published
Aug 15, 2026 by mlissnerModerate -
CourtListener: unscoped visualization JSONVersion create (IDOR) chained to stored XSS in the public embed viewGHSA-cvh7-rv7v-wx2j published
Aug 13, 2026 by mlissnerHigh
Learn more about advisories related to freelawproject/courtlistener in the GitHub Advisory Database