SCA: security update for starlette-admin (GHSA-6753-gr46-6wpr)

medium Tenable Cloud Security Plugin ID 446370

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and
Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and
structured where field names against the configured sortable_fields and searchable_fields allowlists. An
authenticated user with access to an affected list endpoint can submit arbitrary field names to
starlette_admin/base.py and the BaseModelView validation path, bypassing restrictions presented by the
administrative user interface. Requests can sort or filter on fields that are not intended to be sortable
or searchable, causing limited information exposure. Invalid field names and special Python attribute
names such as metadata and the class dunder attribute can also trigger unhandled exceptions and HTTP 500
responses, causing limited denial of service for targeted requests. This issue is fixed in version 0.16.1.
(CVE-2026-54553)

Solution

Update the starlette-admin library and its related packages to version 0.16.1 or later.

See Also

https://github.com/advisories/GHSA-6753-gr46-6wpr

Plugin Details

Severity: Medium

ID: 446370

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/26/2026

Updated: 8/26/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:P

CVSS Score Source: CVE-2026-54553

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/26/2026

Vulnerability Publication Date: 8/26/2026

Reference Information

CVE: CVE-2026-54553