vulny.app on Nostr: Logged-in is not the same as allowed. If a user changes the account ID in the ...
Logged-in is not the same as allowed. If a user changes the account ID in the request, does your code re-check ownership, or just hand the data over?
#cybersecurity #infosec #nostr #appsec #owasp
Published at
2026-07-06 22:18:00 UTCEvent JSON
{
"id": "0fd063fff8367187eb6cea638342302c2a0492fee58593caf445ab5e6f3ca9bb",
"pubkey": "e2eeb88c6504795805452b4e1a1db731dfea087aa7d0ac3e48efbaf0ee416c9d",
"created_at": 1783376280,
"kind": 1,
"tags": [
[
"t",
"cybersecurity"
],
[
"t",
"infosec"
],
[
"t",
"nostr"
],
[
"t",
"appsec"
],
[
"t",
"owasp"
]
],
"content": "Logged-in is not the same as allowed. If a user changes the account ID in the request, does your code re-check ownership, or just hand the data over?\n\n#cybersecurity #infosec #nostr #appsec #owasp",
"sig": "01a59e3864699c1aed00e6cbbdd3035a784758b52613411569e99cc5c89a979283ed3fc06b8910bdd9e643b1ca18613c9b55ffe46fb477e680a59729dbb92e8d"
}