PT-2026-60570 · Npm · Genql

·

CVE-2026-63397

·

Published

2026-07-16

·

Updated

2026-07-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions genql versions prior to 6.3.4
Description An authenticated attacker who can control the GraphQL schema passed to genql can inject arbitrary JavaScript or TypeScript. This malicious code is inserted into the generated schema.ts file and is executed when the genql client is bundled and imported.
Recommendations Update to version 6.3.4 or later.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63397
GHSA-W757-XVVV-VGFW

Affected Products

Genql