zenstack is vulnerable to Exposure of Sensitive Information
95
Critical Risk
Affected versions of the package may expose sensitive information due to improper enforcement of access policies in a polymorphic model hierarchy. Both the base and concrete models in the hierarchy can have access policies, but the access policies directly defined on the concrete models are not properly enforced. As a result, fields that should be excluded, may still be returned, as those marked with @omit on the concrete models, potentially exposing sensitive information.
You are affected if you are using a version which is within vulnerability ranges and if you are using the polymorphic models feature.
zenstack is vulnerable to Exposure of Sensitive Information in versions 1.0.1 - 2.5.1.
Upgrade the zenstack library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant