SCA: security update for @keystone-6/core (GHSA-hg9m-67mm-7pg3)

medium Tenable Self-Hosted Container Security Plugin ID 434761

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access
control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These
filters can be used as an oracle to probe the existence or value of otherwise unreadable fields.
Specifically, when a mutation includes a `where` clause with multiple unique filters (e.g. `id` and
`email`), Keystone will attempt to match records even if filtering by the latter fields would normally be
rejected by `field.isFilterable` or `list.defaultIsFilterable`. This can allow malicious actors to infer
the presence of a particular field value when a filter is successful in returning a result. This affects
any project relying on the default or dynamic `isFilterable` behavior (at the list or field level) to
prevent external users from using the filtering of fields as a discovery mechanism. While this access
control is respected during `findMany` operations, it was not completely enforced during `update` and
`delete` mutations when accepting more than one unique `where` values in filters. This has no impact on
projects using `isFilterable: false` or `defaultIsFilterable: false` for sensitive fields, or for those
who have otherwise omitted filtering by these fields from their GraphQL schema. This issue has been
patched in `@keystone-6/core` version 6.5.0. To mitigate this issue in older versions where patching is
not a viable pathway, set `isFilterable: false` statically for relevant fields to prevent filtering by
them earlier in the access control pipeline (that is, don't use functions); set
`{field}.graphql.omit.read: true` for relevant fields, which implicitly removes filtering by these fields
from the GraphQL schema; and/or deny `update` and `delete` operations for the relevant lists completely.
(CVE-2025-46720)

See Also

https://github.com/advisories/GHSA-hg9m-67mm-7pg3

Plugin Details

Severity: Medium

ID: 434761

Version: Revision 1.13

Type: Local

Family: SCA Checks

Published: 8/19/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2025-46720

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/5/2025

Vulnerability Publication Date: 5/5/2025

Reference Information

CVE: CVE-2025-46720