PT-2026-37175 · Laravel Nova · Nova-Toggle

Robertonegro

·

Published

2026-04-24

·

Updated

2026-05-09

·

CVE-2026-42202

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions nova-toggle-5 versions prior to 1.3.0
Description The toggle endpoint "POST /nova-vendor/nova-toggle/toggle/{resource}/{resourceId}" was protected only by web and auth: middleware. This allowed any user authenticated on the configured guard to flip boolean attributes on any Nova resource, including users without access to Nova. Additionally, the endpoint accepted an arbitrary attribute parameter, enabling callers to toggle any boolean column on the underlying model regardless of whether it was exposed as a Toggle field on the resource.
Recommendations Update to version 1.3.0. As a temporary workaround, remove the package or restrict access to the "/nova-vendor/nova-toggle/toggle/*" routes using additional middleware that enforces the viewNova gate.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42202
GHSA-F5C8-M5VW-RMGQ

Affected Products

Nova-Toggle