Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-65013— Onlook tRPC Insecure Direct Object Reference via multiple procedures

Quick assessment

Affected
onlook repo
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Onlook repo是Onlook公司的一个多仓库管理工具。 Onlook repo 0.2.32及之前版本存在授权问题漏洞,该漏洞源于对象级授权失效,允许经过身份验证的攻击者通过向tRPC API程序(包括project.get、member.remove和chat.conversation.delete)提供任意UUID值来访问和操作其他用户的资源。

CVSS 8.8 · High EPSS 0.52% · P42

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token

Affected Version Matrix 2

VendorProduct Version RangeStatus
onlook repo ≤ 0.2.32 affected
423e2e924366419e418ee049093872d535eea41a unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-65013

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Onlook tRPC Insecure Direct Object Reference via multiple procedures
Source: CVE Program / CVE List V5
Vulnerability Description
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat.conversation.delete. Attackers can provide arbitrary projectId or conversationId values without authorization validation to read, modify, and delete other users' project data, members, and conversation history.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5
Vulnerability Title
Onlook repo 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Onlook repo是Onlook公司的一个多仓库管理工具。 Onlook repo 0.2.32及之前版本存在授权问题漏洞,该漏洞源于对象级授权失效,允许经过身份验证的攻击者通过向tRPC API程序(包括project.get、member.remove和chat.conversation.delete)提供任意UUID值来访问和操作其他用户的资源。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
onlook repo 0 ~ 0.2.32 -

II. Public POCs for CVE-2026-65013

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8251 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-65013

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-65013 (1)

Vendor Advisories for CVE-2026-65013 (1)

Security Blog Posts for CVE-2026-65013 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-65013

No comments yet


Leave a comment