Security guidance for vibe apps
IDOR: when changing an ID exposes another user’s data
IDOR occurs when a route loads an object by ID but does not verify server-side that the current user belongs to that object or tenant.
Reviewed by René Matis · MATIS LABS · Updated 15 August 2026
The scan is free and takes about twenty seconds. You see straight away how many findings there are and how serious they are.
Scan your own app for freeHow to recognise the problem
Common patterns include `/api/projects/:id`, Supabase queries by primary key alone and updates accepting an owner_id supplied by the client.
A working happy path does not prove this boundary. Always test with a second user, while signed out or with an intentionally forbidden input.
How to fix it reliably
Derive user and tenant only from the verified session, bind every query to them and add a two-account negative test.
The control belongs at the server-side trust boundary. A hidden button, different client copy or browser-only validation is not a security control.
Re-test instead of hoping
MLVibeScan checks object access, owner binding and controlled deep signals. A re-test compares the stable protection target with the previous result and reports fixed, partially fixed, unchanged or regression.
Automated checks cover recurring patterns. High-risk business logic may additionally require an individually scoped penetration test.
What we check automatically
- object access, owner binding and controlled deep signals
- Confidence and counter-checking
- Stable fingerprints for re-tests
Frequently asked questions
- Can this be tested from the outside?
- Partly. MLVibeScan checks object access, owner binding and controlled deep signals; source and deep checks require purchase, domain verification and explicit consent.
- Is blocking access in the UI enough?
- No. Security decisions must be enforced server-side for every request, regardless of the client an attacker uses.
- When is the finding fixed?
- Only when the control holds in a controlled re-test and no contradictory source/runtime observation remains.