Researchers documented ORM Leak vulnerabilities in applications that pass user-controlled query parameters directly into ORM filtering APIs. Although ORMs can prevent traditional SQL injection, permissive filters, lookup operators, and relationship traversal can create boolean or error-based oracles that allow attackers to infer protected values character by character, including password hashes, password-reset tokens, API tokens, email addresses, and financial data. Affected patterns span Ruby on Rails Ransack, Django ORM, Beego-based Harbor, Prisma, Entity Framework, and ASP.NET OData; MySQL regular-expression timeouts and PostgreSQL filter behavior can also support error- or time-based inference attacks.
Real-world impact included compromise of a fablabs.io superadmin account after researchers extracted its password-reset token through Ransack queries. Harbor's related issue, tracked as CVE-2025-30086, required subsequent fixes after initial mitigations were bypassed through filter parsing and fuzzy-match behavior; Harbor v2.14.0 added complete-expression validation and approved-operator restrictions. Ransack 4.0.0 likewise changed its defaults to require explicit searchable-attribute and association allow lists. Organizations should never forward arbitrary request data into ORM filters, and should strictly allowlist fields, operators, traversals, and input types while testing relational queries for data inference and resource-exhaustion paths.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers reported Beego's filter-expression parsing behavior to Beego contributors; the behavior could reinterpret a crafted expression such as email__password__startswith as password__startswith.
A warning was added to the Ransack documentation about processing unrestricted user-controlled query parameters.
Harbor v2.14.0 mitigated CVE-2025-30086 by validating the second filter-expression segment against an allow list of approved Beego operators.
Harbor v2.13.1-rc1 attempted to prevent the sensitive-field-filtering bypass by rejecting filter expressions containing more than one double-underscore separator. Its fuzzy-match operator mapping still enabled a bypass using an email__password field expression.
Harbor v2.13.0 introduced filterable metadata and marked User Password and Salt fields as non-filterable in response to CVE-2025-30086. The control validated only the first filter-expression segment and could be bypassed through Beego parsing behavior.
Ransack 4.0.0 changed the default behavior to require explicit allow lists for searchable attributes and associations, addressing unsafe unrestricted filtering patterns.
Researchers reported internet-exploitable critical and high-severity issues caused by unrestricted Ransack filtering in six applications, including CodeOcean, Pageflow, Active Admin, openSUSE Travel Support Program, fablabs.io, and PrepMod. They also identified several hundred additional potentially affected applications.
Researchers abused unrestricted Ransack association filtering to extract a reusable superadmin password-reset token, reset the account password, and promote their own account to superadmin. The compromise exposed phone numbers, email addresses, password hashes for about 60,000 users, and an API token for sensitive user data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
elttam.com
Open sourceelttam.com
Open sourceelttam.com
Open sourcepositive.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.