Information Disclosure in Vendure Open-Source Headless Commerce Platform
CVE-2026-63461
5.3MEDIUM
What is CVE-2026-63461?
The Vendure open-source headless commerce platform contains a vulnerability that allows unauthenticated users to exploit the public Shop API. Prior to version 3.6.5, the API's products, collections, and facets queries improperly handled visibility guards in conjunction with filters provided by callers. Specifically, when using the 'OR' operator for filters, unauthorized access to hidden entities could occur, resulting in the potential retrieval of disabled products and private collections or facets. This issue has been addressed in version 3.6.5, reinforcing the integrity of the API.
Affected Version(s)
vendure >= 1.0.0, < 3.6.5
