Vulnerability GHSA-9g87-32v6-3c2r

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
October 06, 2026 at 03:38 PM UTC
Payload: Sort queries could expose protected field information
0.1.137 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26
0.1.137 - 3.87.1 and 4.0.0-canary.0 - 4.0.0-canary.26

Summary

Payload: Sort queries could expose protected field information

Details

Impact

Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.

You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.

Patches

Payload now applies field-level access checks to sort fields before executing queries.

Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 03:38 PM UTC
Fixed (3.88.0)
1 month ago
August 11, 2026 at 08:55 PM UTC
Fixed (4.0.0-canary.27)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 03:46 PM UTC