-
Unintended Permission Escalation
-
Drafts are mandatorily tied to teams in current version
-
Sharing a view-only Draft link grants recipients access to ALL files within the parent team
-
Flawed Permission Management
-
Shared users don't appear in sidebar Admin panel (Edu plan)
-
Removal requires hidden path:
All Projects → Team name dropdown → Member list
-
Security Risks
-
Uncontrolled permission scope may lead to data breaches
-
Obfuscated management path increases operational risks
-
Reproduction Steps
① Create Draft under any team
② Generate/view-only link and share
③ Recipient gains access to entire team files
④ Removal attempt fails in Admin panel
⑤ Must use: All Projects → Team dropdown → Manage members