Multiple authorization vulnerabilities in Unleash admin API, including a critical missing await that completely bypasses a permission check.
await on Permission Check (HIGH)File: src/lib/features/segment/segment-controller.ts (line 345)
POST /api/admin/segments/strategies has permission: NONE at the route level. The handler performs its own check via this.accessService.hasPermission(), but omits the await keyword. Since hasPermission() is async (returns Promise<boolean>), the variable always receives a truthy Promise object. The if (!hasFeatureStrategyPermission) check never triggers.
// BUG: missing await - hasPermission() returns Promise<boolean>
const hasFeatureStrategyPermission = this.accessService.hasPermission(
req.user, UPDATE_FEATURE_STRATEGY, projectId, environmentId,
);
if (!hasFeatureStrategyPermission) { // Always false - Promise is truthy!
res.status(403).send();
return;
}
Impact: Any authenticated user can modify segment assignments on ANY strategy across ALL projects.
Fix: Add await: const hasFeatureStrategyPermission = await this.accessService.hasPermission(...)
File: src/lib/routes/admin-api/project/variants.ts (line 213-223)
GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants completely ignores projectId. getVariantsOnEnv() only uses featureName and environment.
Impact: Any authenticated user can read variant configs (names, weights, payloads) from any project.
File: src/lib/features/feature-toggle/feature-toggle-controller.ts (line 1107-1116)
GET .../strategies/:strategyId ignores all params except strategyId. Any authenticated user can read any strategy's full configuration.
File: src/lib/features/feature-toggle/feature-toggle-service.ts (line 1611)
getEnvironmentInfo() doesn't validate feature belongs to project. Compare with getFeature() which calls validateFeatureBelongsToProject().
File: src/lib/features/feature-toggle/feature-toggle-controller.ts (line 576-596)
PUT /:projectId/tags accepts features array in body without validating they belong to projectId.
{
"cwe_ids": [
"CWE-639",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-22T20:36:42Z",
"nvd_published_at": null,
"severity": "HIGH"
}