CVE-2026-45413: Insecure Mock File Upload Idor

Detected construction of a mock file object combined with a hardcoded ownership source type during serialization/upload. Failing to conditionally associate correct ownership identities (like checking for specific module IDs) bypasses access controls and introduces Insecure Direct Object Reference (IDOR) vulnerabilities via file uploads. Set metadata dynamica

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-45413-insecure-mock-file-upload-idor --engine opengrep

Description

Detected construction of a mock file object combined with a hardcoded ownership source type during serialization/upload. Failing to conditionally associate correct ownership identities (like checking for specific module IDs) bypasses access controls and introduces Insecure Direct Object Reference (IDOR) vulnerabilities via file uploads. Set metadata dynamica