Cross-tenant read access to project exports via unvalidated export identifier
- Affected asset
- GET /v1/exports/{exportId}/download
- Description
- The export download endpoint validated that the caller was authenticated but did not verify that the requested export belonged to the caller's tenant. Export identifiers were sequential integers.
- Technical impact
- Any authenticated user could download data exports (CSV) generated by other tenants by iterating identifiers.
- Business impact
- Bulk exposure of customer data across tenants; likely contractual breach and notification obligations.
GET /v1/exports/20417/download HTTP/2Authorization: Bearer <tenant-A member token>HTTP/2 200 OKContent-Disposition: attachment; filename="projects-tenant-B.csv"Reproduction steps
- 1.Authenticate as a Member of tenant A and create an export; note the returned exportId (e.g. 20418).
- 2.Request /v1/exports/20417/download with the same token.
- 3.Observe a 200 response with a file belonging to a different tenant.
Remediation
- Enforce tenant ownership on export lookup server-side (WHERE tenant_id = caller.tenant_id).
- Use random, non-sequential identifiers (UUIDv4 or similar) for exports as defense in depth.
- Add an automated authorization test for this endpoint.
References
Retest result
Remediated
Ownership check added; cross-tenant requests now return 404. Verified on September 2, 2026.