CVE-2026-79348
MEDIUM
4,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
https://github.com/mighty840/kitchenasty
https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/controll…
https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/routes/r…
https://github.com/mighty840/kitchenasty/pull/43
https://github.com/mighty840/kitchenasty/security/advisories/GHSA-2w4m-hjg2-2v92