OSV 1.4.0 · github-reviewed · 修改于 2026-08-21 02:38
发布时间
2026-08-21 02:38
GitHub 审查时间
2026-08-21 02:38
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-vgmv-8xjc-6rch/GHSA-vgmv-8xjc-6rch.json
Backpack CRUD's list and read operations correctly apply any query scopes
registered via addClause() / addBaseClause() (e.g. tenant isolation, user
ownership). However, the Update, Delete, and Reorder operations
bypassed these scopes, fetching records directly from the unscoped model query.
An authenticated user who knows or can guess a record's primary key could therefore update, delete, or reorder records that should be invisible to them — a classic IDOR on write paths.
Applications that rely on addBaseClause for row-level access control
(multi-tenancy, per-user data isolation) are affected.
Any Backpack CRUD panel that uses addBaseClause or addClause to restrict
which rows a user may access is affected on its write operations.
An authenticated low-privilege user can modify or delete records belonging to
other tenants / users.
Apply the fixed release for your major version:
The fix ensures Update, Delete, and Reorder all resolve records through the same scoped query used by the read side.
If you cannot upgrade immediately, add explicit Gate / Policy checks in your
CrudController's update(), destroy(), and reorder() methods to verify
the authenticated user is permitted to act on the resolved record.
Reported by Vishal Shukla (@shukla304).