GHSA-9g87-32v6-3c2r

Suggest an improvement
Source
https://github.com/advisories/GHSA-9g87-32v6-3c2r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9g87-32v6-3c2r/GHSA-9g87-32v6-3c2r.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9g87-32v6-3c2r
Aliases
Published
2026-10-06T15:38:32Z
Modified
2026-10-06T15:45:09Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload: Sort queries could expose protected field information
Details

Impact

Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.

You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.

Patches

Payload now applies field-level access checks to sort fields before executing queries.

Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-06T15:38:32Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / payload

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.88.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9g87-32v6-3c2r/GHSA-9g87-32v6-3c2r.json"

npm / payload

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0-canary.0
Fixed
4.0.0-canary.27

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9g87-32v6-3c2r/GHSA-9g87-32v6-3c2r.json"