CVE-2024-6302: Conduit

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.

Affected products

  • Conduit Conduit: before 0.7.0 (fixed in 0.7.0)

Published 2024-06-25. Last modified 2026-06-17.