Vulnerability GHSA-9g87-32v6-3c2r
Summary
Payload: Sort queries could expose protected field information
Details
Impact
Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.
You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.
Patches
Payload now applies field-level access checks to sort fields before executing queries.
Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.
Related Vulnerabilities
Other vulnerabilities affecting the same packages