Executive brief
eLabFTW is an open-source electronic lab notebook used by researchers to manage experiments and data. A security flaw allows logged-in users to see the titles of experiments or resources they are not authorized to access by performing specific numeric searches. While the full content of these records remains protected, the exposure of titles could leak sensitive information such as project names or patient identifiers.
Technical details
An information disclosure vulnerability exists in eLabFTW's search and numeric reference functionality. Due to improper authorization checks during specific numeric-based queries, the application may return the titles of resources (experiments or items) that the requesting user does not have permission to access. The attack vector is network-based and requires the attacker to be authenticated with standard user privileges. The impact is limited to the disclosure of resource titles (CWE-200); access to the actual resource content or metadata beyond the title remains blocked by existing access controls. The issue is resolved in version 5.4.2.
Affected products
- eLabFTW eLabFTW < 5.4.2
Timeline
- 2026-05-29: advisory: GitHub Security Advisory published by vendor
- 2026-06-01: disclosed: NVD publication date
- 2026-06-01: patched: Version 5.4.2 released to address the issue