Impact
The vulnerability in @grpc/grpc-js causes the exact path matcher used for role‑based access control to perform a prefix comparison when case‑insensitive matching is enabled. This means that when one service method name is a prefix of another, the request for the longer method may be matched against the shorter method’s security rule. As a result, an attacker could gain access to a protected method or bypass restrictions intended for a different method, compromising the confidentiality and integrity of the. This is a classic case of improper authorization (CWE‑187) combined with confusion over matching semantics (CWE‑863).
Affected Systems
The issue affects the grpc-node implementation of gRPC in JavaScript, specifically versions prior to 1.13.1 and 1.14.1. Any deployment of these versions that relies on RBAC for method‑level security and enables case‑insensitive matching is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. However, the flaw allows unauthorized method access if an attacker can trigger a request for a method whose name is prefixed by a more permissive rule. The most likely attack vector is a crafted gRPC request sent to an affected server where RBAC rules have overlapping prefixes.
OpenCVE Enrichment
Github GHSA