PT-2026-60570 · Npm · Genql
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
genql versions prior to 6.3.4
Description
An authenticated attacker who can control the GraphQL schema passed to genql can inject arbitrary JavaScript or TypeScript. This malicious code is inserted into the generated
schema.ts file and is executed when the genql client is bundled and imported.Recommendations
Update to version 6.3.4 or later.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Genql