lomkit/laravel-rest-api is vulnerable to Incorrect Authorization
65
Medium Risk
The package authorizes nested relation sync and toggle mutations using only the view ability instead of update. A caller with view access to a related record and update access to the parent can fill attributes onto the related model, writing fields without update permission. The nested sync and toggle attributes are also not checked against the resource's update validation rules, so arbitrary values pass unvalidated. The fix requires the update ability for mutations and applies the update validation rules to sync and toggle.
You are affected if you are using a version that falls within the vulnerable range and you expose resources whose related records rely on update authorization or validation.
lomkit/laravel-rest-api is vulnerable to Incorrect Authorization in versions 2.0.0 - 2.23.1.
Upgrade the lomkit/laravel-rest-api library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant