A vulnerability in OpenReview allows unauthorized access to anonymous identities
openreview.net·6w·
Preview
Report Post

Article:

At 10:09 AM EST today the OpenReview team was notified by the ICLR Workflow Chair of a security vulnerability in our API that allowed unauthorized access to the identities of normally anonymous roles (reviewers, authors, and area chairs) across venues through a specific profile search API endpoint. A software patch blocking unauthorized access was deployed within one hour of the initial report.

Timeline of Response:

  • 10:09 AM: Issue reported by ICLR 2026 Workflow Chair
  • 10:12 AM: OpenReview team acknowledged receipt and began investigation
  • 11:00 AM: Fix deployed to api.openreview.net
  • 11:08 AM: Fix deployed to api2.openreview.net
  • 11:10 AM: Program Chairs and Workflow Chair notified of resolution

The vulnerability allowed queries to the profiles/search en…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help