CVE-2026-29788 Details
Description
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports. This issue has been patched in version 30.
A vulnerability in TSPortal, the WikiTide Foundation's platform for managing Trust and Safety reports, allows users to forge self-deletion requests. This issue affects versions prior to 30. The vulnerability arises from the default behavior of Laravel's middleware, which converts empty strings to null, creating a loophole for DPA reports. When a report is filed about another user without any evidence, it falsely appears as if the user requested deletion of their data. This misrepresentation can lead to unauthorized deletion of user data, both within TSPortal and in subsequent systems where the deletion is processed.
Users can update to TSPortal version 30 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/miraheze/TSPortal/security/advisories/GHSA-gfhq-7499-f3f2 | [email protected] | ExploitVendor Advisory |
| https://issue-tracker.miraheze.org/T15053 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input | [email protected] |
| CWE-283 | Unverified Ownership | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wikitide tsportal | < 30 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | New CVE Received | [email protected] |