CVE-2026-2207: Meteor Publish Unauthorized Id Aggregation
A Meteor publish function aggregates items into an array without conducting an authorization check involving the user ID (e.g., `this.userId`). If this array is used to fetch related items, it can lead to Insecure Direct Object Reference (IDOR) and data leakage. Add an explicit authorization check inside the iteration loop or ensure the initial query correct
greprules fetch cve-2026-2207-meteor-publish-unauthorized-id-aggregation --engine opengrepDescription
A Meteor publish function aggregates items into an array without conducting an authorization check involving the user ID (e.g., `this.userId`). If this array is used to fetch related items, it can lead to Insecure Direct Object Reference (IDOR) and data leakage. Add an explicit authorization check inside the iteration loop or ensure the initial query correct
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.