Vulnerability GHSA-238x-w2j9-gwwr

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 06, 2026 at 04:18 PM UTC
Payload vulnerable to API key disclosure through ordinary document reads
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload vulnerable to API key disclosure through ordinary document reads

Details

Impact

Users with read access to other user documents could access their active API keys. An exposed key grants the target account’s permissions until rotated or disabled.

You are affected if:

  • An authentication collection enables useAPIKey.
  • Users have read access to other user documents containing active API keys.

Patches

Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Disable useAPIKey or restrict users to reading only their own authentication document. Rotate any API key that may have been exposed.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 04:18 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 04:30 PM UTC