Hasura GraphQL 1.3.3 contains a server-side request...
Moderate severity
Unreviewed
Published
Dec 23, 2025
to the GitHub Advisory Database
•
Updated Dec 23, 2025
Description
Published by the National Vulnerability Database
Dec 22, 2025
Published to the GitHub Advisory Database
Dec 23, 2025
Last updated
Dec 23, 2025
Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially access internal network resources.
References