Junglewise Threat Intelligence

CVE-2026-48771: ishankportfolio contact form exposure via insecure database configuration

CVE-2026-48771 · Severity: high · CVSS 8.2 · Published 2026-08-11

Executive brief

ishankportfolio is a portfolio website that includes a contact form for visitor inquiries. Prior to version 1.0.1, the contact form submissions containing personally identifiable information (names, email addresses, phone numbers, messages) could be directly accessed and modified by unauthorized attackers due to improperly configured database security rules and exposed credentials. An attacker with network access could read, modify, or abuse all stored contact form data without any authentication.

Technical details

This vulnerability stems from insufficient access control on client-side database configuration, allowing contact form data to be exposed via publicly accessible database credentials or overly permissive database rules. The attack vector is network-based with no authentication required and no user interaction needed; an attacker can directly query the exposed database to read or modify contact form submissions. The root cause is the lack of Row Level Security (RLS) policies and improper environment variable handling for sensitive credentials. The patch in version 1.0.1 implements secure RLS policies, restricts anonymous access permissions, protects environment variables, and adds server-side validation. Until patched, users should rotate exposed API keys, disable public database access, implement authentication-only policies, and move sensitive operations to backend functions.

Affected products

  • Ishankjha740 ishankportfolio prior to 1.0.1

Timeline

  • 2026-05-22: disclosed: GitHub security advisory GHSA-44fc-h2mc-cw9g published
  • 2026-05-22: patched: Fix released in version 1.0.1
  • 2026-08-11: advisory: CVE-2026-48771 published on NVD

References