Impact
APITable versions up to 1.13.0-beta.1 contain a fault in the NodePermissionGuard that fails to enforce node-level access control when permission lookups raise exceptions; this allows an authenticated attacker to write attachments to datasheets they are explicitly denied from accessing, effectively bypassing authorization. The vulnerability is an instance of improper validation of authority control, enabling unauthorized data modification.
Affected Systems
Vendors affected are APITable (apitable:apitable). The product is the APITable Fusion API, and the affected releases are all builds through the 1.13.0-beta.1 release. No specific patch version is listed, but security updates addressing the guard issue have been applied in subsequent releases.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as a moderate severity vulnerability. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. The vulnerability can be exploited by an attacker who already possesses a valid Fusion API token; the exploit relies on inducing a permission lookup exception to trigger a fail‑open state in the guard, thereby allowing the attacker to write attachments to private datasheets they have no right to access.
OpenCVE Enrichment