Executive brief
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb
Affected products
- Go github.com/authzed/spicedb
Junglewise Threat Intelligence
CVE-2025-49011 · Severity: low · CVSS 3.1 · Published 2025-06-10
Technologies: github.com/authzed/spicedb (Go). Vendors: Go.
SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb