GHSA-7hh3-3x64-v2g9

    Dashboard / Vulnerabilities / GHSA-7hh3-3x64-v2g9

    GHSA-7hh3-3x64-v2g9

    Published: 20 Jun 2023Last Modified: 10 Sept 2026

    Summary: When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id

    Details: ### Impact If you used the [apiPrefilter](https://remult.dev/docs/ref_entity.html#apiprefilter) option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attacker who knows the `id` of an entity instance she is not authorized to access, can gain read, update and delete access to it. ### Patches The issue is fixed in version 0.20.6 ### Workarounds Set the `apiPrefilter` option to a filter object instead of a function. ### References If you're using a minor version < 0.20 and require a patch, please create an issue.

    Affected packages

    Package

    Name: remult

    Purl: pkg:npm/remult

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.20.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7hh3-3x64-v2g9 | CVE-DB