CVE-2021-41248 is a dynamic Cross-Site Scripting (XSS) vulnerability affecting GraphiQL versions older than 1.4.7, where malicious GraphQL type names in schema introspection responses or schema prop values can lead to code injection during operation autocomplete. The attack requires a user to load a vulnerable schema, which is more readily exploitable in custom GraphiQL implementations allowing dynamic schema URL configuration. Rated Medium (CVSS 4.7), the attack has high complexity and requires user interaction, but can result in partial loss of confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.5.0, < 1.4.7CPE matchmatch criteria | cpe:2.3:a:graphql:graphiql:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.