Onlook Web Application tRPC APIs Broken Object Level Authorization Vulnerability

Vulnerability

A Broken Object Level Authorization (BOLA) vulnerability has been identified in the Onlook web application version 0.2.32, specifically within the tRPC project mutation APIs that handle updates, deletions, and tag management. This vulnerability arises because the API does not properly verify whether the authenticated user owns or is a member of the project associated with the requested ID. As a result, an authenticated attacker could exploit this flaw by sending a request that includes another user's project ID, allowing them to unlawfully modify, delete, or manipulate tags on that project. Such actions could significantly disrupt data integrity and availability.

Impact

Exploitation of this vulnerability could lead to unauthorized modifications, deletions, or manipulations of project data and tags, severely disrupting data integrity and availability.

Added: Nov 7, 2025, 4:17 PM
Updated: Nov 7, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
4.8
remediation
0.0
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.