CVE-2026-53901: Premature Unset Mass Assignment
Sanitizing an input array by unsetting restricted fields (like 'id') before applying an input normalization or transformation routine is vulnerable if the transformation step can reconstruct or hoist the restricted field back into the output array. Move the sanitization to occur strictly after the transformation, on the fully normalized data.
greprules fetch cve-2026-53901-premature-unset-mass-assignment --engine opengrepDescription
Sanitizing an input array by unsetting restricted fields (like 'id') before applying an input normalization or transformation routine is vulnerable if the transformation step can reconstruct or hoist the restricted field back into the output array. Move the sanitization to occur strictly after the transformation, on the fully normalized data.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.