Improper Input Validation in Starlette-Admin by Jowilf
CVE-2026-54553
5.4MEDIUM
What is CVE-2026-54553?
Starlette-Admin prior to version 0.16.1 contains an improper input validation vulnerability within its list API. This allows authenticated users to bypass restrictions by supplying arbitrary field names for sorting and filtering, potentially exposing sensitive information or causing unhandled exceptions. It can lead to HTTP 500 responses, which may result in denial of service for targeted requests. This issue has been addressed in version 0.16.1, enhancing the security controls of field validation.
Affected Version(s)
starlette-admin < 0.16.1
