PT-2026-53669 · Hasura+1 · Hasura+1
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Mythic versions prior to 3.4.0.60
Description
A broken Hasura permission filter exists on the
payload build step table. This issue involves an always-satisfied or condition that bypasses operation-scoped access controls. Consequently, authenticated operators and spectators can query the payload build step table to read the step stdout, step stderr, step name, and step description variables across all operations on the server.Recommendations
Update to version 3.4.0.60 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hasura
Mythic