Intel

AIKIDO-2026-323789

@vendure/core is vulnerable to Improper Privilege Management

Improper Privilege ManagementGHSA-v85r-wfgv-jcqc Published Today

91

Critical Risk

This Affects:

JS@vendure/core
0.14.0 - 3.7.1
Fixed in 3.7.2
Are you affected? Scan for Free

TL;DR

The Admin API updateAdministrator mutation allows an administrator with UpdateAdministrator permission to assign the SuperAdmin role and reset credentials for a target administrator without enforcing the target role boundary. A channel-scoped administrator can use this path to take over a SuperAdmin account and gain unrestricted control of the Vendure instance. The fix prevents non-SuperAdmin callers from updating SuperAdmin accounts or assigning the SuperAdmin role.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and permit non-SuperAdmin administrators to update administrator accounts.

Background info

@vendure/core is vulnerable to Improper Privilege Management in versions 0.14.0 - 3.7.1.

How to fix this

Upgrade the @vendure/core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform