Technologyglobal✓ verified · 90%
Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
- When
- Where
- Global (internet)
- Category
- cyber_advisory · composer
The `recordSelectOptionsQuery()` method may be used to scope the options available in the `Select` field for `AttachAction` and `AssociateAction`. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value.
Sources
- GitHub Advisory Database ↗ · first seen 2026-06-11 20:26 UTC
Defaxon links out to the original reporting and never republishes article text.
Correlated events
Computed by the Defaxon correlation engine — linked by shared actors, co-location, and temporal proximity. Scored hypotheses, never causal claims.
No correlated events found in the current window. As more events arrive, connections form automatically.