CVE-2025-66402: Typeorm Insecure Relation Export
Eagerly loading data with relations via TypeORM's `find()` and directly exporting or serializing it might bypass access controls for the related entities. Use a QueryBuilder to apply authorization constraints on joins, or perform access checks within the loop before serialization or processing.
greprules fetch cve-2025-66402-typeorm-insecure-relation-export --engine opengrepDescription
Eagerly loading data with relations via TypeORM's `find()` and directly exporting or serializing it might bypass access controls for the related entities. Use a QueryBuilder to apply authorization constraints on joins, or perform access checks within the loop before serialization or processing.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.