Junglewise Threat Intelligence

CVE-2026-65013: Onlook IDOR in tRPC API procedures

CVE-2026-65013 · Severity: high · CVSS 8.8 · Published 2026-07-22

Executive brief

Onlook, a visual development tool, contains a security flaw where logged-in users can access or delete data belonging to other users. By manipulating unique identifiers in web requests, an attacker could read private project data, delete conversation histories, or remove legitimate members from projects they do not own. This could lead to significant data loss and unauthorized exposure of intellectual property.

Technical details

A Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in multiple tRPC API procedures in Onlook. The root cause is that the Drizzle ORM database client connects using a Postgres superuser role that bypasses Row Level Security (RLS), and the application failed to implement manual authorization checks in several tRPC routers. Authenticated attackers can provide arbitrary UUIDs for parameters such as projectId, conversationId, or branchId to bypass membership requirements. Affected procedures include project.get, member.remove, and chat.conversation.delete. The vulnerability was addressed in commit 423e2e9 by implementing a resolve-then-verify pattern across all project-scoped procedures.

Affected products

  • Onlook Onlook repo through 0.2.32

Timeline

  • 2026-06-01: disclosed: Vulnerability reported to vendor via email
  • 2026-07-21: patched: Fix committed to main branch
  • 2026-07-22: advisory: CVE published to NVD

References