Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
2917
Downloads
3.3M
Verified
2917
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2026-21621: Insecure Api Scope Mappingcve-2026-21621-insecure-api-scope-mapping

The codebase incorrectly grants the full over-privileged `["api"]` scope whenever a permission's domain is `"api"`, completely ignoring the resource qualifier (such as `"read"`). This can lead to privilege escalation where a read-only API key is granted full write access. Map permissions correctly by taking resource qualifiers into account, or delegate to a

by Provallyupdated 2026-06-23Apache-2.0
7430 direct743 via packs
downloads
68quality
All matching rules loaded.