Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
4797
Downloads
7.5M
Verified
4797
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2026-32248: Parse Logical Op Arraylike Bypasscve-2026-32248-parse-logical-op-arraylike-bypass

Iteration over Parse logical operators ('$or', '$and', '$nor') guards recursion with only Array.isArray, which allows an attacker-supplied array-like plain object (e.g. {"0": {...}, "length": 1}) to bypass the check. Downstream query / matching / protected-field code may still iterate the value via numeric/length-based access. Add an explicit pre-check that

by Provallyupdated 2026-06-12Apache-2.0
2.5K0 direct2.5K via packs
downloads
80quality
All matching rules loaded.