Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.0 RubyGems

graphql allows remote code execution when loading a crafted GraphQL schema

GHSA-q92j-grw3-h492 · CVE-2025-27407

Published · Modified

Description

Summary

Loading a malicious schema definition in GraphQL::Schema.from_introspection (or GraphQL::Schema::Loader.load) can result in remote code execution. Any system which loads a schema by JSON from an untrusted source is vulnerable, including those that use GraphQL::Client to load external schemas via GraphQL introspection.

Ready to move

Start Securing

Free, no credit card | First findings in minutes