{"id":"GHSA-9pm8-vwc5-w2hm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-9pm8-vwc5-w2hm","summary":"Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID","details":"### Impact\n\nAuthenticated users can delete emails imported into the system assigned to another user; where the [Email Dropbox](https://github.com/fatfreecrm/fat_free_crm/wiki/Email-Dropbox) is in use.\n\n### Patches\n\nFixed in v0.26.0\n\n### Workarounds\n\nDisable use of email dropbox.","published":"2026-04-14T01:07:01Z","modified":"2026-04-14T01:25:46.759995Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"fat_free_crm","fixedVersion":"0.26.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/fatfreecrm/fat_free_crm/security/advisories/GHSA-9pm8-vwc5-w2hm"},{"type":"PACKAGE","url":"https://github.com/fatfreecrm/fat_free_crm"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-14T01:25:46.759995Z"}}