CVE-2023-30956: Palantir Foundry Comments

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.

Affected products

  • Palantir Foundry Comments: before 2.267.0 (fixed in 2.267.0)

Published 2023-07-10. Last modified 2026-06-17.