Mass Assignment
Also known as:Autobinding
Mass Assignment: Unfiltered binding of request fields to an object, allowing protected attributes to be set. The vulnerability is an authorizationAuthorizationDecision regarding which actions an authenticated identity is permitted to perform. gap in an API’s write path.
How it works and where it fits
Many frameworks automatically bind incoming JSON or form fields to model attributes. That convenience becomes a risk as soon as the set of bindable fields is not explicitly constrained: the attacker adds fields that never appear in the form — role, is_admin, verified, balance, owner_id — and the framework accepts them without complaint. The attack requires no authentication bypass, only a legitimate session and an extended request body.
Practical security relevance
Remediation lies in an explicit allowlist of bindable fields per endpoint, separate objects for input and persistence, and server-side enforcement of security-relevant attributes independent of the request. During testing it pays to use a read response body as the field list for write attempts — fields an API emits, it often also accepts. The finding rarely appears alone and should be examined together with BOLABroken Object Level AuthorizationMissing check of whether the caller is allowed to access the specific object requested..
Related concepts
- AuthorizationAuthorizationDecision regarding which actions an authenticated identity is permitted to perform.: Decision regarding which actions an authenticated identity is permitted to perform.
- Input ValidationInput ValidationVerification of input data regarding format, length, type, value range, and validity.: Verification of input data regarding format, length, type, value range, and validity.
- API SecurityAPI SecurityProtects APIs against misuse, unauthorized access, and data-related attacks.: Protects APIs against misuse, unauthorized access, and data-related attacks.
- Insecure Direct Object ReferenceInsecure Direct Object ReferenceAccess control flaw where object identifiers enable unauthorized access.: Access control flaw where object identifiers enable unauthorized access.