Loading the catalog…
Loading the catalog…
spree_api
high severity · CVSS 7.1 · CWE-639 · rubygems spree_api · affected >= 5.4.0, < 5.4.4 · fixed in 5.4.4
What RADAR observed and classified to build this opportunity. It is what the source published, not a verification that the offer is still active.
CVE-2026-94462: Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) — spree_api, fixed in 5.4.4
Open sourceThe catalog shows persisted RADAR opportunities. Storage availability does not mean sources are verified or offers are active.