How to use this reference
Editorial lesson: a guest object needs an explicit authorization model even when no account owns it. Keep object identification separate from evidence of permission. The maintainer lists patched releases 5.0.8, 5.1.10, 5.2.7 and 5.3.2; this record does not independently verify their implementation.
Before reading
- Basic object-level access-control concepts
- Familiarity with web request and response processing
Context and limits
- Exposure requires an affected storefront and a completed guest order identifier. Neither a signed-in account nor victim interaction is required; account-owned orders are not established as affected.
- The maintainer describes a controlled demonstration exposing guest-order details. GHSL identifies potential disclosure of names, addresses and phone numbers. No customer incident, measured data loss, write access or account takeover is established.
- GHSL records reporting on January 26, 2026 and publication of fixes and the maintainer advisory on February 5. The detailed research was published March 12. Resource edition release remains unknown and is separate from product patch chronology.
- The maintainer affected-version shorthand is ambiguous; do not interpret it as normalized branch ranges. Patched versions are reproduced as listed.
- The research byline is Peter Stöckli. Discovery is credited to GitHub Security Lab Taskflow Agent, with manual verification by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial.
Sources and provenance
- GHSL-2026-029: Insecure Direct Object Reference (IDOR) in Spree - CVE-2026-25757 GitHub Security Lab · reviewed 2026-10-03
- Unauthenticated users can view completed guest orders by Order ID Spree · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.