Description
A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.0
References
- GHSA-c73g-mx2w-cc93
- vuldb.com
- CVE-2025-12919
- CWE-639
- CWE-99
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- EverShop at risk to unauthorized access via weak HMAC secret - CVE-2023-46943
- @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor - CVE-2026-8766
- Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools - CVE-2025-9611
- evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API - CVE-2025-67427
You might also like:
- Tags:
- npm
- @evershop/evershop
Anything's wrong? Let us know Last updated on December 12, 2025


