Intel

AIKIDO-2025-10926

@convex-dev/rate-limiter is vulnerable to Authorization Bypass Through User-Controlled Key

Authorization Bypass Through User-Controlled Key Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 11, 2025

75

High Risk

This Affects:

JS@convex-dev/rate-limiter
0.3.1 - 0.3.1
Fixed in 0.3.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper validation of client-provided keys, allowing attackers to pass arbitrary keys un-validated, which could be exploited by supplying malicious keys to bypass security measures, such as accessing unauthorized data or executing privileged actions through key manipulation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@convex-dev/rate-limiter is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.3.1 - 0.3.1.

How to fix this

Upgrade the @convex-dev/rate-limiter library to the patch version.