Answer in brief
CVE-2026-108730 records a Medium severity (CVSS 5.3) vulnerability in Raven 2.0.0 through 3.0.0 Missing Authorization via Legacy Message and File APIs. The current sources do not mark it as known exploited. The current feed maps The-Commit-Company/raven (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps The-Commit-Company/raven (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| The-Commit-Company/ravengeneric | >=2.0.0 <=3.0.0 | Not reported |
Published upstream
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 11, 2026
Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability in legacy methods in raven/api/raven_message.py that skip the workspace membership check. Authenticated non-members can call get_messages_with_dates or get_all_files_shared_in_channel with predictable channel IDs to read Public channel history and Open/Public channel file metadata across workspaces.
Quoted source text, attributed separately from HOL analysis.