CVE-2025-63783

A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The vulnerability exists because the API fails to verify the ownership or membership of the currently authenticated user for the requested project ID. An authenticated attacker can send a malicious request containing another user's project ID to unlawfully modify, delete, or manipulate tags on that project, which can severely compromise data integrity and availability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:onlook:onlook:0.2.32:*:*:*:*:*:*:*

History

05 Feb 2026, 16:25

Type Values Removed Values Added
References () https://blog.soohyun.tech/CVE-2025-63783-IDOR-in-Onlook-27a557175d2e8061a3dbc931da53f095 - () https://blog.soohyun.tech/CVE-2025-63783-IDOR-in-Onlook-27a557175d2e8061a3dbc931da53f095 - Exploit, Third Party Advisory
References () https://tossbank.notion.site/IDOR-in-onlook-27a557175d2e8061a3dbc931da53f095 - () https://tossbank.notion.site/IDOR-in-onlook-27a557175d2e8061a3dbc931da53f095 - Broken Link
CPE cpe:2.3:a:onlook:onlook:0.2.32:*:*:*:*:*:*:*
First Time Onlook
Onlook onlook

12 Nov 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6
CWE CWE-20

07 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-07 16:15

Updated : 2026-02-05 16:25


NVD link : CVE-2025-63783

Mitre link : CVE-2025-63783

CVE.ORG link : CVE-2025-63783


JSON object : View

Products Affected

onlook

  • onlook
CWE
CWE-20

Improper Input Validation