github.com/netbirdio/netbird is vulnerable to Authorization Bypass Through User-Controlled Key
82
High Risk
Affected versions of this package are vulnerable to account impersonation due to insufficient validation of the ?account= query parameter in the management server’s authentication middleware. An authenticated user could provide an arbitrary account ID when accessing the /api/peers/<peer_id>/accessible-peers endpoint and potentially access accounts they are not authorized to control. The issue is fixed by adding explicit validation with IsValidChildAccount(), ensuring account switching is only allowed for legitimate child accounts.
You are affected if you are using a version that falls within the vulnerable range.
github.com/netbirdio/netbird is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.1 - 0.64.5.
Upgrade the github.com/netbirdio/netbird library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant