{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/onlook--0.2.32/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-65013"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Onlook (\u003c= 0.2.32)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","api-abuse","cve"],"_cs_type":"advisory","_cs_vendors":["Onlook"],"content_html":"\u003cp\u003eA critical broken object level authorization (BOLA) vulnerability, identified as CVE-2026-65013, has been discovered in Onlook software, affecting versions up to and including 0.2.32. This flaw allows an authenticated attacker to bypass authorization checks within the application's tRPC API. By crafting requests with arbitrary UUIDs (e.g., \u003ccode\u003eprojectId\u003c/code\u003e, \u003ccode\u003econversationId\u003c/code\u003e) for specific procedures like \u003ccode\u003eproject.get\u003c/code\u003e, \u003ccode\u003emember.remove\u003c/code\u003e, and \u003ccode\u003echat.conversation.delete\u003c/code\u003e, attackers can gain unauthorized access to other users' project data, modify member information, and delete conversation histories. This vulnerability poses a significant risk of data breach, integrity compromise, and denial of service for affected users, as it enables full control over sensitive data and user accounts belonging to other individuals on the same platform. The vulnerability was fixed in commit 423e2e9.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated attacker gains access to a legitimate user account within the vulnerable Onlook application.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies tRPC API procedures susceptible to broken object level authorization, specifically \u003ccode\u003eproject.get\u003c/code\u003e, \u003ccode\u003emember.remove\u003c/code\u003e, and \u003ccode\u003echat.conversation.delete\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker intercepts or crafts API requests for these target procedures.\u003c/li\u003e\n\u003cli\u003eThe attacker replaces the legitimate UUIDs (e.g., \u003ccode\u003eprojectId\u003c/code\u003e, \u003ccode\u003econversationId\u003c/code\u003e) in the request parameters with arbitrary UUIDs belonging to other users or resources they do not own.\u003c/li\u003e\n\u003cli\u003eThe Onlook application processes these requests without performing adequate authorization checks to verify if the authenticated user has legitimate access to the supplied arbitrary UUID.\u003c/li\u003e\n\u003cli\u003eThe application performs the requested action (read, modify, delete) on the resources associated with the arbitrary UUID, effectively bypassing object-level authorization.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully reads other users' project data, removes members from projects, or deletes other users' chat conversation histories, achieving unauthorized data access, manipulation, or destruction.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65013 allows authenticated attackers to fully compromise the privacy and integrity of other users' data within the Onlook platform. Attackers can gain complete unauthorized access to sensitive project data, modify or delete critical information, and disrupt collaboration by removing project members. Furthermore, they can delete entire conversation histories, leading to significant data loss and potential compliance issues. While specific victim counts are not available, all users of Onlook versions 0.2.32 and earlier are at risk, with potential consequences including reputational damage, financial losses due to data breaches, and a complete loss of trust in the platform's security.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65013 by updating Onlook to a version beyond 0.2.32, specifically incorporating the fix from commit 423e2e9, immediately.\u003c/li\u003e\n\u003cli\u003eImplement API gateway logging and monitoring to detect unusual patterns in tRPC API calls, such as repeated attempts to access various \u003ccode\u003eprojectId\u003c/code\u003e or \u003ccode\u003econversationId\u003c/code\u003e values by a single user, specifically for procedures like \u003ccode\u003eproject.get\u003c/code\u003e, \u003ccode\u003emember.remove\u003c/code\u003e, and \u003ccode\u003echat.conversation.delete\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eReview application-level logs for signs of unauthorized data access, modification, or deletion linked to arbitrary UUID values.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T17:19:43Z","date_published":"2026-07-22T17:19:43Z","id":"https://feed.craftedsignal.io/briefs/2026-07-onlook-bola/","summary":"An authorization bypass vulnerability, CVE-2026-65013, exists in Onlook through version 0.2.32, allowing authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures such as project.get, member.remove, and chat.conversation.delete without proper authorization, leading to unauthorized data exposure, modification, or deletion.","title":"CVE-2026-65013: Onlook Broken Object Level Authorization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-onlook-bola/"}],"language":"en","title":"CraftedSignal Threat Feed - Onlook (\u003c= 0.2.32)","version":"https://jsonfeed.org/version/1.1"}