CVE-2026-71214: Nasa-Ammos Plandev Sequencing-Server
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura.
Affected products
- Nasa-Ammos Plandev Sequencing-Server: version 0 only
Published 2026-08-05. Last modified 2026-08-26.