Vulnerabilities/

StudioCMS has Authorization Bypass Through User-Controlled Key

Severity:
Medium

Description

StudioCMS contains a Broken Object Level Authorization (BOLA) vulnerability in the Content Management feature that allows users with the “Visitor” role to access draft content created by Editor/Admin/Owner users.

Recommendation

Update the studiocms package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
studiocms
Anything's wrong? Let us know Last updated on January 29, 2026