CVE-2025-46720 Details
Description
Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an oracle to probe the existence or value of otherwise unreadable fields. Specifically, when a mutation includes a `where` clause with multiple unique filters (e.g. `id` and `email`), Keystone will attempt to match records even if filtering by the latter fields would normally be rejected by `field.isFilterable` or `list.defaultIsFilterable`. This can allow malicious actors to infer the presence of a particular field value when a filter is successful in returning a result. This affects any project relying on the default or dynamic `isFilterable` behavior (at the list or field level) to prevent external users from using the filtering of fields as a discovery mechanism. While this access control is respected during `findMany` operations, it was not completely enforced during `update` and `delete` mutations when accepting more than one unique `where` values in filters. This has no impact on projects using `isFilterable: false` or `defaultIsFilterable: false` for sensitive fields, or for those who have otherwise omitted filtering by these fields from their GraphQL schema. This issue has been patched in `@keystone-6/core` version 6.5.0. To mitigate this issue in older versions where patching is not a viable pathway, set `isFilterable: false` statically for relevant fields to prevent filtering by them earlier in the access control pipeline (that is, don't use functions); set `{field}.graphql.omit.read: true` for relevant fields, which implicitly removes filtering by these fields from the GraphQL schema; and/or deny `update` and `delete` operations for the relevant lists completely.
A vulnerability exists in Keystone prior to version 6.5.0, allowing a bypass of the `{field}.isFilterable` access control in `update` and `delete` mutations. This is achieved by introducing additional unique filters, which can be used to probe the existence or value of otherwise unreadable fields. When a mutation's `where` clause includes multiple unique filters, Keystone may match records even if the latter fields would typically be excluded by `field.isFilterable` or `list.defaultIsFilterable`. This could enable malicious actors to infer the presence of specific field values based on successful filter matches. This vulnerability impacts any project that relies on the default or dynamic `isFilterable` settings to restrict external users from using field filtering as a discovery tool. While `findMany` operations respect this access control, it is not fully enforced during `update` and `delete` mutations that accept multiple unique `where` filters. Projects that have set `isFilterable: false` or `defaultIsFilterable: false` for sensitive fields, or have excluded these fields from their GraphQL schema, are not affected.
Users can upgrade to Keystone version 6.5.0 or later, where this vulnerability has been patched. For projects on older versions where upgrading is not possible, relevant fields can be set to `isFilterable: false` or `defaultIsFilterable: false`, or `update` and `delete` operations can be denied for the affected lists.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/keystonejs/keystone/security/advisories/GHSA-hg9m-67mm-7pg3 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-203 | Observable Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| keystonejs keystone | < 6.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 19, 2025 | Initial Analysis | [email protected] |
| May 5, 2025 | New CVE Received | [email protected] |