Intel

AIKIDO-2025-10293

@liveblocks/react-ui is vulnerable to Missing Authorization

Missing Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

10

Low Risk

This Affects:

js@liveblocks/react-ui
2.0.0 - 2.24.1
Fixed in 2.24.2

TL;DR

Affected versions of this package fail to disable or hide UI actions properly (e.g., adding comments, resolving/unresolving threads) for users without the necessary permissions. An attacker can exploit this issue by interacting with seemingly available actions despite lacking proper authorization, potentially leading to manipulating thread states or adding reactions, disrupting discussions, and misusing privileged functions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@liveblocks/react-ui is vulnerable to Missing Authorization in versions 2.0.0 - 2.24.1.

How to fix this

Upgrade the @liveblocks/react-ui library to the patch version.