PT-2026-41127 · Tuist · Tuist
Highpepicrft
·
Published
2026-05-14
·
Updated
2026-05-15
·
CVE-2026-44678
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Tuist versions prior to 1.180.9
Description
The "DELETE /api/projects/{account handle}/{project handle}/previews/{preview id}" endpoint loads a preview by its UUID without verifying that the preview belongs to the project resolved from the URL path. The project-level authorization plug
AuthorizationPlug, :preview authorizes the caller against the project encoded in account handle and project handle, which can be controlled by an attacker, allowing the deletion of any preview UUID supplied.Recommendations
Update to a version later than 1.180.8.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tuist