PT-2026-48945 · Typesense · Typesense

CVE-2026-47225

·

Published

2026-06-12

·

Updated

2026-06-12

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Typesense versions prior to 29.1 Typesense versions prior to 30.2
Description A cache isolation issue exists affecting search requests that utilize both server-side search result caching and Scoped Search API Keys with embedded filters. Under specific request ordering, cached search results may be reused across requests that have different Scoped Search API Key constraints. This can lead to the unintended disclosure of search results across scoped authorization contexts, allowing a request to receive results that should have been restricted.
Recommendations Update to version 29.1. Update to version 30.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47225
GHSA-97X4-GM45-JPCW

Affected Products

Typesense