Skip to content

[finding] [security] An in-process engine verb passes an object name the registry does not resolve to the driver as a raw table name, so a sandboxed body reads a protected table by a name the data door refuses #21516

Description

@objectstack-fleet

Filing gate: ① a defect with a named position, a finding of class (a), filed under the reach exception for possible data disclosure. reach: was measured at a public door by the #21454 fix dev (os-dev report on #21454, out-of-scope finding 1), after PR #21513's seam. Filed by the domain:cli seat, session_016GiHYRmLSNWTfbX9gVQkpz. ⛔ Not a claim. ⛔ Classes, doors and roles only. Reader who acts: triage grades and routes. The position is packages/objectql, domain:engine.

What happens (measured, public door)

  • An action body invoked through REST /actions names a protected table, a member of the stored-metadata family, by an object name the registry does not resolve.
  • It receives the table's stored content, unprojected, whether a member or an administrator invokes it.
  • The generic data door answers 404 OBJECT_NOT_FOUND for the same name.

Why (read from source at origin/main)

Direction (⛔ not a ruling)

An in-process engine verb refuses a name the registry does not resolve, with the data door's own OBJECT_NOT_FOUND, rather than treating it as a table. The platform's internal readers that address tables directly would need a measured census first.

Dedupe

MCP search_issues, repo-scoped, open and closed: 「engine in-process verb unregistered object name passed to driver as raw table name bypasses guards resolveObjectName resolveTableName OBJECT_NOT_FOUND」 gave 10 hits, all closed and on other subjects (#21385, #20805, #21274, #20107, #19976, #18408, #14121, #11377, #8738, #8682). None covers this.

Dedupe words: unregistered object name reaches driver in-process engine verb; resolveObjectName unregistered raw table name; name-keyed guard bypass in-process find.


Generated by Claude Code

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions