Executive brief
Tuist is a platform used by Apple developers to manage and share app previews. A security flaw in the preview deletion system allows any registered user to delete app previews belonging to other organizations or users. This could lead to data loss and disruption of development workflows, as deleted previews and their associated build records can only be recovered from backups.
Technical details
An Insecure Direct Object Reference (IDOR) exists in the `DELETE /api/projects/{account_handle}/{project_handle}/previews/{preview_id}` endpoint. The `AuthorizationPlug` validates the requester's permissions against the project specified in the URL path (which the attacker controls), but the backend logic subsequently deletes the preview identified by the `preview_id` UUID without verifying that it actually belongs to that project. Because `AppBuilds.preview_by_id/2` performed a global lookup without scoping to the resolved project, an authenticated attacker can delete any preview by providing its UUID. This affects both Tuist Cloud and self-hosted deployments. The vulnerability was addressed by scoping the database lookup to the project ID resolved from the URL.
Affected products
- Tuist Tuist Server <= 1.180.8
Timeline
- 2026-05-04: advisory: GitHub advisory published
- 2026-05-14: disclosed: CVE published to NVD