zenstack is vulnerable to Improper Access Control
91
Critical Risk
Affected versions of the package are vulnerable to improper access control. ZenStack internally uses { AND: [] } to represent constant true and { OR: [] } for constant false. However, Prisma provides inconsistent query results in certain nesting combinations, which can allow unauthenticated users to read from tables.
You are affected if you are using a version that falls within the vulnerable range.
zenstack is vulnerable to Improper Access Control in versions 0.1.0 - 2.3.3.
Upgrade the zenstack library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant