Prisma's vulnerability profile centers on GraphQL Playground, a developer-focused tool distributed across multiple middleware and runtime variants including Express, Koa, and Lambda deployments. The observed exposure recurs through code-injection and cross-site scripting weaknesses characteristic of dynamic code-generation and templating contexts within web development tooling; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prisma over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21415HIGH Prisma VS Code a VSCode extension for Prisma schema files. This is a Remote Code Execution Vulnerability that affects all versions of the Prisma VS Code extension older than 2.20.0 | Apr 29, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-21414HIGH Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` package who are affected by this | Apr 29, 2021 | 7.2 | 24 | NO | NO |
CVE-2020-4038HIGH GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlayg | Jun 8, 2020 | 7.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prisma.
Media articles that mention a CVE ID that affects a product developed by Prisma — matched by CVE ID, not by vendor name.