PT-2026-48945 · Typesense · Typesense
CVE-2026-47225
·
Published
2026-06-12
·
Updated
2026-06-12
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Typesense versions prior to 29.1
Typesense versions prior to 30.2
Description
A cache isolation issue exists affecting search requests that utilize both server-side search result caching and Scoped Search API Keys with embedded filters. Under specific request ordering, cached search results may be reused across requests that have different Scoped Search API Key constraints. This can lead to the unintended disclosure of search results across scoped authorization contexts, allowing a request to receive results that should have been restricted.
Recommendations
Update to version 29.1.
Update to version 30.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typesense