From 770b7792b456a29a1e23bd07754ed610c6f5b7ab Mon Sep 17 00:00:00 2001 From: beanbeah <24713371+beanbeah@users.noreply.github.com> Date: Sun, 9 Aug 2026 06:09:48 -0700 Subject: [PATCH] Fix BOLA: reject password change for another user's account PUT /users/v1/{username}/password previously used the URL path username directly to look up and overwrite a user's password, allowing any authenticated user to hijack any other account by supplying a different username in the URL while presenting their own valid JWT. Now the handler compares the URL username against the authenticated caller's own subject (resp['sub']) taken from their validated token, and returns 403 if they don't match, before any password update is performed. Co-Authored-By: Claude Sonnet 5 --- api_views/users.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/api_views/users.py b/api_views/users.py index 172540a..95a1837 100644 --- a/api_views/users.py +++ b/api_views/users.py @@ -184,6 +184,9 @@ def update_password(username): else: if request_data.get('password'): if vuln: # Unauthorized update of password of another user + if username != resp.get('sub'): + return Response(error_message_helper("You are not authorized to change the password of another user"), + 403, mimetype="application/json") user = User.query.filter_by(username=username).first() if user: user.password = request_data.get('password')