Impact
In Vendure versions prior to 3.6.5, the public Shop API for products, collections, and facets combines mandatory visibility checks with caller‑supplied filters. When the caller supplies filterOperator=OR, a predicate that matches a hidden entity can bypass the Product.enabled, Collection.isPrivate, or Facet.isPrivate guard. As a result an unauthenticated client can retrieve disabled or private items, exposing non‑public information. The flaw stems from improper handling of logical OR in filter expressions.
Affected Systems
The vulnerability affects installations of the Vendure headless commerce platform by VendureHQ, specifically any version prior to 3.6.5, and is confined to the Shop API endpoints that return lists of products, collections, or facets. Upgrade to Vendure 3.6.5 or later resolves the problem.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not known to be actively exploited. An attacker would simply send an unauthenticated request to the public Shop API with filterOperator set to OR and a filter that matches a hidden entity; no special privileges are required. Because the flaw allows the retrieval of private data, the primary risk is information disclosure. The lack of known exploitation and the moderate score suggest that while the vulnerability should be addressed promptly, it is unlikely to be a high‑threat target.
OpenCVE Enrichment
Github GHSA