Wednesday, September 23, 2026
3 changes · 19.0
Security fixes and vulnerability patches
This pull request fixes several issues in Odoo’s core processing tools, including safer handling of emails, images, logs, templates, profiling, and test data generation. It reduces the risk of credential leaks, improves resilience against malformed or heavy inputs, and prevents user-facing errors in common backend operations.
Original PR description
Description of the issue/feature this PR addresses: Current behavior before PR: Desired behavior after PR is merged: --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr
This fix prevents referrers from downloading attachments for referred applicants when they are not otherwise allowed to access those applicant records. It protects sensitive recruitment documents by ensuring job-level attachment lists only include applicants visible to the current user.
Original PR description
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce:…
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce: ---------------------------------------- - Install hr_recruitment and hr_referral - Create two applicants for the same job position - Make another user the interviewer of the first one and the referrer of the second - Add an attachment to the second user - Connect as this user - In recruitment, go to the job position page - Click on the attachment button at the top - The user can download the attachment even though they can't access the applicant because they aren't their interviewer Cause: ---------------------------------------- The rule `hr_applicant_referral_user_rule` gives a referrer read access to the `hr.applicant` record they referred, so we can show them a few safe fields (`partner_name`, `job_id`, etc.). But they cannot see the applicant because of the field `is_accessible_to_current_user` added in `hr_referral` to prevent access to non interviewer users. `action_open_attachments` lists attachments of every application on the job from `application_ids`, without checking `is_accessible_to_current_user`, so it leaks attachments of applications the current user can only access as a referrer. Solution: ---------------------------------------- Create `_get_attachments_domain()` which will check `is_accessible_to_current_user` with an override in `hr_referral`. opw-6446049 Forward-Port-Of: odoo/odoo#288236 Forward-Port-Of: odoo/odoo#283547
This fix prevents referral users from opening or downloading attachments for job applicants they are not allowed to access. It protects sensitive recruitment documents by ensuring job-level attachment lists only include applicants visible to the current user.
Original PR description
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce:…
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce: ---------------------------------------- - Install hr_recruitment and hr_referral - Create two applicants for the same job position - Make another user the interviewer of the first one and the referrer of the second - Add an attachment to the second user - Connect as this user - In recruitment, go to the job position page - Click on the attachment button at the top - The user can download the attachment even though they can't access the applicant because they aren't their interviewer Cause: ---------------------------------------- The rule `hr_applicant_referral_user_rule` gives a referrer read access to the `hr.applicant` record they referred, so we can show them a few safe fields (`partner_name`, `job_id`, etc.). But they cannot see the applicant because of the field `is_accessible_to_current_user` added in `hr_referral` to prevent access to non interviewer users. `action_open_attachments` lists attachments of every application on the job from `application_ids`, without checking `is_accessible_to_current_user`, so it leaks attachments of applications the current user can only access as a referrer. Solution: ---------------------------------------- Create `_get_attachments_domain()` which will check `is_accessible_to_current_user` with an override in `hr_referral`. opw-6446049 Forward-Port-Of: odoo/enterprise#131519 Forward-Port-Of: odoo/enterprise#128597