Vulnerability library
Security checkApril 22, 2026

@saltcorn/data: Tenant user role is used for tenant creation role check

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpm@saltcorn/data

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

When a tenant admin is logged out of the root domain (e.g., saltcorn.com) but logged in to their own tenant space as admin, they can simply append /tenant/create to their tenant URL.

Recommendation

Update the @saltcorn/data package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 1.6.0-alpha.0, < 1.6.0-beta.2 >= 1.5.0-beta.0, < 1.5.2 < 1.4.4**
  • Patched version(s): **1.6.0-beta.2 1.5.2 1.4.4**

References

Could your website be exposed too?

SmartScanner can check your website for @saltcorn/data: Tenant user role is used for tenant creation role check and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated April 22, 2026