Executive brief
A security vulnerability exists in the Cedar authorization middleware for Express.js applications. This middleware is used to control access to different parts of a web application based on security policies. An attacker can bypass these security checks by adding specific characters to a web address, potentially gaining unauthorized access to sensitive administrative functions or private user data.
Technical details
The vulnerability is an interpretation conflict (CWE-436) between the Cedar authorization middleware and the Express.js framework. The middleware uses 'req.originalUrl' (which includes the query string) to match requests against Cedar action mappings, while Express routes requests based only on the path component. In applications with overlapping path prefixes (e.g., /users and /users/:id), an attacker can append a query string (e.g., /users/?x=1) to cause the middleware to match a less restrictive policy (like a single user view) while Express executes the more restrictive handler (like the full user list). This allows a remote authenticated attacker to bypass intended authorization constraints. The issue is fixed in version 0.3.0 by switching to 'req.path' for action matching.
Affected products
- AWS @cedar-policy/authorization-for-expressjs <= 0.2.0
Timeline
- 2026-05-07: patched: Version 0.3.0 released
- 2026-05-26: disclosed: Initial disclosure date
- 2026-06-30: advisory: GitHub Advisory published/reviewed