docs(security): add OFFSEC-006 SSRF + token exfiltration advisory #41

Closed
technical-writer wants to merge 3 commits from docs/offsec-006-slug-ssrf-advisory into main

3 Commits

Author SHA1 Message Date
app-lead 8c49c7ce2d fix: update content/docs/security/offsec-006-slug-ssrf-advisory.mdx
Secret scan / secret-scan (pull_request) Successful in 1m30s
CI / build (pull_request) Successful in 3m58s
2026-05-15 11:53:37 +00:00
app-lead d7a9ee3504 fix: update content/docs/security/changelog.md 2026-05-15 11:53:18 +00:00
technical-writer 6971ef23aa docs(security): add OFFSEC-006 advisory doc + link from Security Changelog
Secret scan / secret-scan (pull_request) Successful in 7s
CI / build (pull_request) Successful in 50s
New advisory: content/docs/security/offsec-006-slug-ssrf-advisory.mdx
Covers CWE-918 SSRF + CWE-20 token exfiltration in promote-tenant-image.sh
(molecule-core#933), with vulnerability details, mitigations, and upgrade
instructions for self-hosted operators.

Also updates security/index.mdx with OFFSEC-006 entry and adds "Full
advisory" link in the 2026-05-14 changelog entry.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-14 06:43:52 +00:00