diff --git a/Gemfile b/Gemfile
index 3f2c4997f0afa985efa46098b4d0373a7761d295..f7b0aeb605ba7384421c8bc84376636d7e542c4b 100644
--- a/Gemfile
+++ b/Gemfile
@@ -12,7 +12,8 @@ gem "bootsnap", "~> 1", require: false
 gem "bootstrap5-kaminari-views"
 gem "breadcrumbs_on_rails"
 gem "bugsnag"
-gem "cancancan", "~> 3"
+# Lock précis parce que @sebouchu a identifié un problème
+gem "cancancan", "~> 3.3.0"
 gem "caxlsx_rails", "~> 0"
 gem "citeproc", "~> 1"
 gem "citeproc-ruby", "~> 2"
diff --git a/Gemfile.lock b/Gemfile.lock
index 90375d11b8f9fc9ffcb20c9ed7d900517a474123..023fe9f7cc47f73d11cb69d1f0da736b41f8803a 100644
--- a/Gemfile.lock
+++ b/Gemfile.lock
@@ -120,7 +120,7 @@ GEM
     autoprefixer-rails (10.4.16.0)
       execjs (~> 2)
     aws-eventstream (1.3.0)
-    aws-partitions (1.873.0)
+    aws-partitions (1.874.0)
     aws-sdk-core (3.190.1)
       aws-eventstream (~> 1, >= 1.3.0)
       aws-partitions (~> 1, >= 1.651.0)
@@ -153,7 +153,7 @@ GEM
       concurrent-ruby (~> 1.0)
     builder (3.2.4)
     byebug (11.1.3)
-    cancancan (3.5.0)
+    cancancan (3.3.0)
     capybara (3.39.2)
       addressable
       matrix
@@ -629,7 +629,7 @@ DEPENDENCIES
   breadcrumbs_on_rails
   bugsnag
   byebug
-  cancancan (~> 3)
+  cancancan (~> 3.3.0)
   capybara (>= 3.26)
   caxlsx_rails (~> 0)
   citeproc (~> 1)