encore.dev is vulnerable to Authentication Bypass
91
Critical Risk
Encore API endpoints that do not require authentication can still query whether a user authenticated. For those endpoints the authentication gateway ignores the inbound X-Encore-Meta-UserID header instead of stripping it, so a request can set that header and have upstream services treat it as a legitimate authenticated user, spoofing the user id. Endpoints that require authentication are handled correctly and are not affected. The fix strips all inbound x-encore-meta-* headers for requests that are not from a verified internal caller and re-derives the metadata before signing and forwarding it.
You are affected if you are using a version that falls within the vulnerable range and you expose API endpoints that do not require authentication but still read the authenticated user.
encore.dev is vulnerable to Authentication Bypass in versions 0.0.1 - 1.57.10.
Upgrade the encore.dev library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant