Vendure: Shop API list queries can return non-public entities when filterOperator is OR
GHSA-xf65-r35x-wmmv · CVE-2026-63461
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
The Shop API products, collections and facets queries inject a mandatory filter to restrict results to publicly-visible entities (Product.enabled = true, Collection.isPrivate = false, Facet.isPrivate = false). This injected guard was combined with the caller-supplied filter using the caller-controlled filterOperator. When a caller sets filterOperator: OR, the guard is OR-combined instead of AND-combined, so a caller can retrieve disabled products and private collections/facets by supplying a predicate that matches them.
Impact
Exposure of catalog entities intended to be hidden from the Shop API. The Shop API is publicly accessible, so no authentication is required.
Patches
The injected guard is now always AND-combined with the caller-supplied filter, regardless of filterOperator.
Workarounds
None other than upgrading.
Ready to move
Start Securing
Free, no credit card | First findings in minutes