{"id":"CVE-2026-79348","published":"2026-09-29T20:17:26.583","lastModified":"2026-09-29T20:17:26.583","description":"KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://github.com/mighty840/kitchenasty","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/controllers/reservation.controller.ts","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/routes/reservation.routes.ts","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/pull/43","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/security/advisories/GHSA-2w4m-hjg2-2v92","tags":[]}],"exploitRefs":[{"url":"https://github.com/mighty840/kitchenasty","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/controllers/reservation.controller.ts","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/routes/reservation.routes.ts","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/pull/43","tags":[]},{"url":"https://github.com/mighty840/kitchenasty/security/advisories/GHSA-2w4m-hjg2-2v92","tags":[]}],"hasPoc":true,"ai":null}