sort_by query parameter is a NoSQL injection vector #64

Open
opened 2026-03-30 13:29:56 +00:00 by sharang · 0 comments
Owner

findings.rs takes sort_by verbatim from query params and injects into MongoDB sort doc. Allows sorting by internal fields. Fix: Validate against an allowlist of permitted sort fields.

findings.rs takes sort_by verbatim from query params and injects into MongoDB sort doc. Allows sorting by internal fields. Fix: Validate against an allowlist of permitted sort fields.
sharang added the securitybughighv0.3.0 labels 2026-03-30 13:29:56 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sharang/compliance-scanner-agent#64