—
GO-2026-5133
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb
Quick fix
GO-2026-5133 — github.com/authzed/spicedb: upgrade to the fixed version with the command below.
go get github.com/authzed/spicedb@v1.54.0Details
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected in github.com/authzed/spicedb
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/authzed/spicedb
Introduced in:
1.34.0Fixed in: 1.54.0Fix
go get github.com/authzed/spicedb@v1.54.0