Improper Authorization Affecting almirhodzic/nova-toggle-5 package, versions <1.3.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-ALMIRHODZICNOVATOGGLE5-16379925
  • published4 May 2026
  • disclosed24 Apr 2026
  • creditRobertoNegro

Introduced: 24 Apr 2026

NewCVE-2026-42202  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade almirhodzic/nova-toggle-5 to version 1.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authorization via the toggle endpoint. An attacker can modify boolean fields on any resource by sending requests to the endpoint with arbitrary attribute parameters, even if they do not have access to the Nova admin area, as long as they are authenticated on the configured guard. This is only exploitable if the application uses a shared authentication guard between frontend users and the Nova admin area.

Workaround

This vulnerability can be mitigated by restricting access to the /nova-vendor/nova-toggle/toggle/* routes via an additional middleware that enforces the viewNova gate.

CVSS Base Scores

version 4.0
version 3.1