turso
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/multi-tenant.md
LOWAnomalyLOW
references/multi-tenant.md
The fragment is legitimate multi-tenant provisioning and migration documentation with no clear malware or supply-chain backdoor indicators. It presents meaningful security risks if used unchanged: unvalidated tenant identifiers, possible cross-tenant access, use of a broad organization token for database access, potentially overbroad read_attach permissions, and execution of arbitrary SQL across all tenant databases. Tenant identity must be authorized independently of URL construction, identifiers should be validated and encoded, database tokens should be least-privileged and scoped, and migration input must be trusted and controlled.
Confidence: 97%Severity: 67%
Audit Metadata