CVE-2026-65013

Source
https://cve.org/CVERecord?id=CVE-2026-65013
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65013.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-65013
Published
2026-07-22T16:14:23.346Z
Modified
2026-07-25T04:14:49.851749494Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Onlook tRPC Insecure Direct Object Reference via multiple procedures
Details

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat.conversation.delete. Attackers can provide arbitrary projectId or conversationId values without authorization validation to read, modify, and delete other users' project data, members, and conversation history.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65013.json"
}
References

Affected packages

Git / github.com/onlook-dev/onlook

Affected ranges

Type
GIT
Repo
https://github.com/onlook-dev/onlook
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.2.32"
        }
    ]
}

Affected versions

v0.*
v0.2.32

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65013.json"