Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid credentials or session cookies. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3ghg-3787-w2xr Spree API has Unauthenticated IDOR - Guest Address
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 10 Jan 2026 03:45:00 +0000

Type Values Removed Values Added
Description Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid credentials or session cookies. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.
Title Spree API has Unauthenticated IDOR - Guest Address
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-10T03:17:58.494Z

Reserved: 2026-01-07T21:50:39.532Z

Link: CVE-2026-22589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-10T04:16:01.343

Modified: 2026-01-10T04:16:01.343

Link: CVE-2026-22589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses