What is CVE-2026-65013?
CVE-2026-65013 is a broken object level authorization vulnerability in Onlook through 0.2.32, allowing authenticated attackers to access and manipulate other users' resources by injecting arbitrary UUIDs into tRPC API procedures. It is fixed in commit 423e2e9, so users should upgrade to the patched version immediately.
Azərbaycanca: CVE-2026-65013 'Onlook' alətində authenticated attacker-lərə UUID manipulyasiyası ilə digər istifadəçilərin resurslarına icazəsiz giriş imkanı verən broken object level authorization zəifliyidir. 0.2.32 və aşağı versiyalar təsirlənir, commit 423e2e9 ilə düzəldilib. İstifadəçilər dərhal müvafiq commit-i ehtiva edən versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Onlook are affected by CVE-2026-65013?
This vulnerability affects Onlook versions 0.2.32 and below.
What can an authenticated attacker do by exploiting CVE-2026-65013?
By injecting arbitrary UUIDs into tRPC API procedures, an authenticated attacker can gain unauthorized access to and manipulate other users' resources due to broken object level authorization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.