GSSA-2026-04-H5BNHW2026-04-25
4.6 Medium

DISABLE_ENCRYPTION env var silently disables data encryption

Setting `DISABLE_ENCRYPTION=true` made all ticket messages and feedback comments stored in plaintext, with no log warning and no production guardrail. An operator who flipped this for a one-off task and forgot would silently leak all sensitive data going forward.

Setting DISABLE_ENCRYPTION=true made all ticket messages and feedback comments stored in plaintext with no log warning and no production guardrail, so an operator who flipped this for a one-off task and forgot would silently leak all sensitive data going forward.