Vulnerabilities/

StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens

Severity:
Low

Description

The REST API getUsers endpoint in StudioCMS uses the attacker-controlled rank query parameter to decide whether owner accounts should be filtered from the result set.

Recommendation

Update the studiocms package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
studiocms
Anything's wrong? Let us know Last updated on March 18, 2026