PT-2026-79448 · Keystone · Keystone

CVE-2026-63421

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Keystone versions prior to 6.5.3
Description The findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake. This allows a remote unauthenticated GraphQL client to provide a negative take value with a magnitude exceeding the configured bound. This bypass also affects relationship queries and can result in the return of more records than intended, potentially leading to the exhaustion of service resources.
Recommendations Update to version 6.5.3.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63421
GHSA-CQMQ-8755-7XVH

Affected Products

Keystone