WhisperX tag archive

#IDOR vulnerability

This page collects WhisperX intelligence signals tagged #IDOR vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-23 09:54:12 · GitHub Issues

1. HiveLoop Go SaaS Audit Flags Critical Cross-Tenant IDOR Flaws in Router Module

A comprehensive security audit of the HiveLoop Go SaaS backend API has identified four critical-severity vulnerabilities, including two persistent IDOR flaws that expose a fundamental tenant isolation failure in the platform's router module. The audit, covering all approximately 185 endpoints across auth, tenant-scoped...

The Lab · 2026-05-01 23:54:08 · GitHub Issues

2. Authorization Gap in Netlify Functions Exposes Multiple Endpoints to IDOR Attacks

A critical authorization flaw has been identified across several Netlify functions, allowing users to perform actions on resources they do not own. The vulnerability, classified as Insecure Direct Object Reference (IDOR), affects endpoints that accept resource identifiers—including sheetId, folderId, and noteId—without...