Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Weakness
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Potential Mitigations
References