steedos/steedos-platform

steedos/steedos-platform

Releases1.68K
Frequency1 day 11 hours
Last Release
Stars1.56K
The AI-Native Infrastructure for Enterprise Apps. Powered by ObjectStack (ObjectQL, ObjectOS, Object UI). Turn Prompts into Enterprise Software.

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.5 MEDIUM

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.