CVE-2026-54553
Improper validation of order_by/where fields leads to unauthorized sorting, filtering and possible DoS.
- CVSS 5.4
- 200
- Input Validation and Sanitization
- Remote
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlists. An authenticated user with access to an affected list endpoint can submit arbitrary field names to starlette_admin/base.py and the BaseModelView validation path, bypassing restrictions presented by the administrative user interface. Requests can sort or filter on fields that are not intended to be sortable or searchable, causing limited information exposure. Invalid field names and special Python attribute names such as metadata and the class dunder attribute can also trigger unhandled exceptions and HTTP 500 responses, causing limited denial of service for targeted requests. This issue is fixed in version 0.16.1.
- CWE
- 200
- CVSS base score
- 5.4
- Published
- 2026-08-26
- OWASP
- A01 Broken Access Control
- Orthogonal defect classification
- Checking
- Code defect classification
- Missing Check
- Category
- Input Validation and Sanitization
- Subcategory
- Insecure Direct Object References (IDOR)
- Accessibility scope
- Remote
- Impact
- Information Disclosure
- Affected component
- Starlette-Admin
- Fixed by upgrading
- Yes
Solution
Upgrade Starlette‑Admin to version 0.16.1 or later.
Vulnerable code sample
from starlette.requests import Request
from starlette_admin.views import BaseModelView
from starlette_admin import ModelView
class UserView(BaseModelView):
model = "User"
searchable_fields = ["username", "email"]
sortable_fields = ["id", "created_at"]
async def get_query(self, request: Request):
# VULNERABLE: uses user-supplied field names without validation
order_by = request.query_params.get("order_by")
where = request.query_params.get("where")
query = f"SELECT * FROM {self.model}"
if where:
query += f" WHERE {where}"
if order_by:
query += f" ORDER BY {order_by}"
return queryPatched code sample
from starlette.requests import Request
from starlette_admin.views import BaseModelView
from starlette_admin import ModelView
class UserView(BaseModelView):
model = "User"
searchable_fields = ["username", "email"]
sortable_fields = ["id", "created_at"]
async def get_query(self, request: Request):
# FIX: validate order_by and where fields against allowlists
order_by = request.query_params.get("order_by")
where = request.query_params.get("where")
query = f"SELECT * FROM {self.model}"
if where:
field, _, value = where.partition("=")
if field not in self.searchable_fields:
raise ValueError("Invalid filter field")
query += f" WHERE {field} = '{value}'"
if order_by:
if order_by not in self.sortable_fields:
raise ValueError("Invalid sort field")
query += f" ORDER BY {order_by}"
return queryPayload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202654553,
title = {{Improper validation of order_by/where fields leads to unauthorized sorting, filtering and possible DoS.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-54553},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-54553/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
