CVE-2021-23326 is a critical command injection vulnerability affecting versions of the @graphql-tools/git-loader package prior to 6.2.6. It allows unauthenticated attackers to execute arbitrary commands due to the insecure use of exec and execSync functions in the load-git.ts file. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk, enabling full compromise of confidentiality, integrity, and availability with low attack complexity. While no active exploitation, public exploits, or significant community discussion have been observed, the potential for severe impact necessitates prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.2.6CPE matchmatch criteria | cpe:2.3:a:the-guild:graphql-tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.