Skip to content
Noroxi

CWE-639 · 2,471 records

Authorization bypass through user-controlled key

Why does it happen?

The endpoint fetches the record by the ID sent in the request, but never checks whether the record belongs to the requesting user.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
const invoice = await Invoice.findById(req.params.id);res.json(invoice);

Fixed

ts
const invoice = await Invoice.findOne({  id: req.params.id,  ownerId: req.user.id,});if (!invoice) return res.sendStatus(404);res.json(invoice);

How to prevent it

  1. 01Add the session user as a condition to every query.
  2. 02Centralize ownership checks in a single authorization layer.
  3. 03Write cross-access tests using two different accounts.

CVEs in this class

2,474 records

All vulnerability classes