Tandoor Recipes — `amount`/`unit` bypass serializer in `food/{id}/shopping/`
Published Apr 7, 2026
7.3
HIGHCVSS 3.1
EPSS 0.32%
Description
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from request.data and passes them without validation to ShoppingListEntry.objects.create(). Invalid amount values (non-numeric strings) cause an unhandled exception and HTTP 500. A unit ID from a different Space can be associated cross-space, leaking foreign-key references across tenant boundaries. All other endpoints creating ShoppingListEntry use ShoppingListEntrySerializer, which validates and sanitizes these fields. This vulnerability is fixed in 2.6.4.
Affected products
-
- Version < 2.6.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TandoorRecipes | Recipes | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19674 Advisory
- https://github.com/TandoorRecipes/recipes/releases/tag/2.6.4 x_refsource_MISCProductRelease Notes
- https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-8w8h-3pv2-3554 exploitx_refsource_CONFIRMMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19674 | Advisory | |
| https://github.com/TandoorRecipes/recipes/releases/tag/2.6.4 | x_refsource_MISCProductRelease Notes | |
| https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-8w8h-3pv2-3554 | exploitx_refsource_CONFIRMMitigationVendor Advisory |
Change history (0)
No recorded changes yet.