statamic/cms is vulnerable to Improper Access Control
40
Medium Risk
Affected versions of this package are vulnerable to an improper access control issue in the relationship endpoint. The implementation does not sufficiently enforce authorization checks when retrieving related resources, allowing authenticated users to access data beyond their intended permissions. An attacker could exploit this by querying the endpoint to retrieve restricted or non-public content. The issue is addressed by adding proper authorization validation to ensure that only permitted resources are returned.
You are affected if you are using a version that falls within the vulnerable range.
statamic/cms is vulnerable to Improper Access Control in versions 5.0.0 - 5.73.12 and 6.0.0 - 6.6.2.
Upgrade the statamic/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant