Broken Object Level Authorization Vulnerability in Onlook Web Application
CVE-2025-63783

7.6HIGH

Key Information:

Vendor

Onlook

Vendor
CVE Published:
7 November 2025

What is CVE-2025-63783?

A serious vulnerability has been identified in the Onlook web application, specifically within its tRPC project mutation APIs. This flaw allows authenticated attackers to exploit the system by submitting malicious requests that manipulate project IDs they do not own or belong to. By circumventing proper ownership checks, an attacker can modify, delete, or tamper with tags associated with other users' projects, leading to potential data integrity issues and disruptions in service availability. This highlights the critical need for robust authorization mechanisms to safeguard user data and maintain application security.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.