Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
Moderate severity
GitHub Reviewed
Published
May 23, 2026
in
filamentphp/filament
•
Updated Jun 11, 2026
Description
Published to the GitHub Advisory Database
Jun 11, 2026
Reviewed
Jun 11, 2026
Last updated
Jun 11, 2026
The
recordSelectOptionsQuery()method may be used to scope the options available in theSelectfield forAttachActionandAssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value.References