Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
Moderate severity
GitHub Reviewed
Published
May 23, 2026
in
filamentphp/filament
•
Updated Jul 18, 2026
Description
Published to the GitHub Advisory Database
Jun 11, 2026
Reviewed
Jun 11, 2026
Published by the National Vulnerability Database
Jun 22, 2026
Last updated
Jul 18, 2026
The
recordSelectOptionsQuery()method may be used to scope the options available in theSelectfield forAttachActionandAssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value.References