CVE-2026-65013 | Onlook up to 0.2.32 tRPC API projectId/conversationId authorization (423e2e9)
A vulnerability classified as critical was found in Onlook up to 0.2.32. Affected by this vulnerability is the function project.get/member.remove/chat.conversation.delete of the component tRPC API. Such manipulation of the argument projectId/conversationId leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-65013. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More