CVE-2026-34212: Authorization Check And Of Not Equal Throws

Authorization/validation check combines multiple inequality (`!==`) comparisons with logical AND (`&&`) before throwing an error. By De Morgan's law this requires ALL fields to mismatch to reject the request, so a single matching field (e.g. workspaceId in the same workspace) bypasses the entire check. For ownership / scoping checks the conditions should be

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-34212-authorization-check-and-of-not-equal-throws --engine opengrep

Description

Authorization/validation check combines multiple inequality (`!==`) comparisons with logical AND (`&&`) before throwing an error. By De Morgan's law this requires ALL fields to mismatch to reject the request, so a single matching field (e.g. workspaceId in the same workspace) bypasses the entire check. For ownership / scoping checks the conditions should be