MEDIUM 4.3 NVD
CVE-2026-79348
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in p
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
References
- https://github.com/mighty840/kitchenasty
- https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/controllers/reserva
- https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/routes/reservation.
- https://github.com/mighty840/kitchenasty/pull/43
- https://github.com/mighty840/kitchenasty/security/advisories/GHSA-2w4m-hjg2-2v92
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.