{"id":"GHSA-hqxq-hwqf-wg83","summary":"monetr: Protected Transactions Deletable via PUT","details":"### Summary\nA transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transactions through the transaction update endpoint, despite the application explicitly blocking deletion of those transactions via the normal `DELETE` path. This bypass undermines the intended protection for imported transaction records and allows protected transactions to be hidden from normal views.\n\n### Details\nThe issue affects the transaction update path for synced transactions associated with non-manual links. The intended policy is clearly enforced in the `DELETE` handler: deletion of synced transactions for non-manual links is rejected with an error indicating that such transactions cannot be deleted.\n\nHowever, the `PUT` update path still accepts a client-controlled full `Transaction` object and persists fields that should be server-managed, including `deletedAt`. The update logic appears to restrict only selected fields, which leaves `deletedAt` attacker-controllable.\n\nVerified behavior on the same synced transaction showed:\n\n- `DELETE` was denied with the expected protection error for non-manual links\n- `PUT` with a user-supplied `deletedAt` value succeeded and returned `200 OK`\n- a subsequent transaction list no longer showed the transaction\n- `GET` by transaction ID still returned the record with `deletedAt` populated\n\nThis demonstrates a policy bypass: although the server explicitly defines synced transactions on non-manual links as non-deletable through the dedicated delete route, the same outcome can still be achieved through the update route by setting the soft-delete field directly.\n\nThe vulnerability is therefore not a simple UI inconsistency. It is a server-side authorization and integrity flaw caused by trusting a client-supplied full transaction object and failing to protect sensitive server-managed fields from modification.\n\n### PoC\nThe issue can be reproduced by identifying a synced transaction on a non-manual link, confirming that the normal `DELETE` route rejects deletion, then submitting an update request that sets the transaction’s `deletedAt` field. The transaction will then disappear from normal listing views even though direct retrieval still shows the record as soft-deleted.\n\n### Impact\n- **Type:** Authorization bypass / integrity violation\n- **Who is impacted:** Authenticated tenant users and any deployment relying on synced transaction immutability for non-manual links\n- **Security impact:** Attackers can hide or effectively delete protected imported transactions that should not be deletable, compromising transaction history, bookkeeping integrity, and trust in audit-relevant server-managed fields\n- **Attack preconditions:** The attacker must be authenticated and able to access a synced transaction within their own tenant/account scope","aliases":["CVE-2026-39901","GO-2026-5434"],"modified":"2026-07-21T14:53:20Z","published":"2026-04-08T19:23:00Z","database_specific":{"github_reviewed_at":"2026-04-08T19:23:00Z","nvd_published_at":"2026-04-08T22:16:22Z","cwe_ids":["CWE-285"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/monetr/monetr/security/advisories/GHSA-hqxq-hwqf-wg83"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39901"},{"type":"PACKAGE","url":"https://github.com/monetr/monetr"},{"type":"WEB","url":"https://github.com/monetr/monetr/releases/tag/v1.12.3"}],"affected":[{"package":{"name":"github.com/monetr/monetr","ecosystem":"Go","purl":"pkg:golang/github.com/monetr/monetr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.12.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-hqxq-hwqf-wg83/GHSA-hqxq-hwqf-wg83.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N"}]}