Open registration flaw in CoopCycle exposed customer home addresses across tenants

A security researcher, Santosh Kumar Puppala, discovered that the GET /api/stores/{id}/addresses endpoint in CoopCycle's open-source delivery platform carried no authorization check, unlike every other operation on the same resource. Because self-registration is open, any authenticated user could enumerate store IDs and retrieve customer names, street addresses, and postcodes from any store on a shared instance. The flaw affected multi-tenant deployments where a single CoopCycle installation hosts multiple unrelated worker-owned courier co-operatives, making it a platform-wide cross-tenant data leak. The vulnerability was reported under coordinated disclosure and silently patched in commit a65d9f9e within two days, released as version v5.6.0 shortly after. No official advisory has been published, and a CVE assignment is currently pending; the researcher rated the issue CVSS 6.5 (Medium) due to high confidentiality impact.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in