MEDIUM 5.3 npm

Vendure: Shop API list queries can return non-public entities when filterOperator is OR

GHSA-xf65-r35x-wmmv · CVE-2026-63461

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The Shop API products, collections and facets queries inject a mandatory filter to restrict results to publicly-visible entities (Product.enabled = true, Collection.isPrivate = false, Facet.isPrivate = false). This injected guard was combined with the caller-supplied filter using the caller-controlled filterOperator. When a caller sets filterOperator: OR, the guard is OR-combined instead of AND-combined, so a caller can retrieve disabled products and private collections/facets by supplying a predicate that matches them.

Impact

Exposure of catalog entities intended to be hidden from the Shop API. The Shop API is publicly accessible, so no authentication is required.

Patches

The injected guard is now always AND-combined with the caller-supplied filter, regardless of filterOperator.

Workarounds

None other than upgrading.

Ready to move

Start Securing

Free, no credit card | First findings in minutes