CVE-2026-1175 is an information exposure vulnerability affecting birkir prime up to version 0.4.0.beta.0, specifically within the GraphQL Directive Handler component when processing requests to the /graphql endpoint. This high-severity vulnerability (CVSS 7.5) allows remote attackers to gain sensitive information through error messages, requiring no user interaction or privileges. While not yet in CISA's KEV catalog, a public exploit is available, and the vulnerability has garnered significant community discussion, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.4.0CPE matchmatch criteria | cpe:2.3:a:birkir:prime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.