CVE-2026-65013 Details
Description
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat.conversation.delete. Attackers can provide arbitrary projectId or conversationId values without authorization validation to read, modify, and delete other users' project data, members, and conversation history.
A broken object-level authorization vulnerability has been identified in Onlook versions through 0.2.32. This vulnerability allows authenticated users to access and manipulate other users' project resources by sending arbitrary UUIDs to various tRPC API procedures. The affected procedures include project.get, member.remove, and chat.conversation.delete. Exploitation of this vulnerability enables unauthorized users to read, modify, and delete project data, manage project members, and alter conversation histories of other users.
The vulnerability has been addressed in Onlook version 0.2.32. Users should update to this version or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 22, 2026CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/onlook-dev/onlook/issues/3122 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/onlook-dev/onlook/commit/423e2e924366419e418ee049093872d535eea41a | [email protected] | Source CodeVendor |
| https://github.com/onlook-dev/onlook/issues/3122 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/onlook-dev/onlook/pull/3129 | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/onlook-trpc-insecure-direct-object-reference-via-multiple-procedures | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Onlook | <= 0.2.32 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |
Volerion