CVE-2025-63783

A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The vulnerability exists because the API fails to verify the ownership or membership of the currently authenticated user for the requested project ID. An authenticated attacker can send a malicious request containing another user's project ID to unlawfully modify, delete, or manipulate tags on that project, which can severely compromise data integrity and availability.
Configurations

No configuration.

History

12 Nov 2025, 17:15

Type Values Removed Values Added
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6

07 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-07 16:15

Updated : 2025-11-12 17:15


NVD link : CVE-2025-63783

Mitre link : CVE-2025-63783

CVE.ORG link : CVE-2025-63783


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation