Executive brief
GraphQL Playground is a web-based IDE for developing and testing GraphQL APIs. The vulnerability allows attackers to inject malicious JavaScript code into the playground interface when unsanitized user input (such as endpoint URLs) is passed to the rendering functions. A victim visiting a specially crafted link could have arbitrary code executed in their browser, potentially leading to session hijacking, credential theft, or unauthorized actions on the platform hosting the playground.
Technical details
This is a reflected XSS vulnerability (CWE-79) in the GraphQL Playground HTML rendering engine and its middleware wrappers. The vulnerability stems from unsanitized user input being passed directly to the renderPlaygroundPage() function and related middleware functions (expressPlayground, koaPlayground, lambdaPlayground, hapiPlayground) without proper HTML escaping or input validation. Attack vectors include URL parameters like "endpoint" that are reflected in the generated HTML. An attacker crafts a malicious URL containing JavaScript payloads and sends it to a victim; when the victim visits the link, the JavaScript executes in their browser with the same privileges as the web application. User interaction (clicking the malicious link) is required. The vulnerability affects graphql-playground-html versions before 1.6.22 and all dependent middleware packages. Patches are available: upgrade to graphql-playground-html@1.6.22+, graphql-playground-middleware-express@1.7.16+, graphql-playground-middleware-koa@1.6.15+, graphql-playground-middleware-lambda@1.7.17+, and graphql-playground-middleware-hapi@1.6.13+. Workarounds include manual input sanitization using libraries like @braintree/sanitize-url.
Affected products
- Prisma Labs graphql-playground-html < 1.6.22
- Prisma Labs graphql-playground-middleware-express < 1.7.16
- Prisma Labs graphql-playground-middleware-koa < 1.6.15
- Prisma Labs graphql-playground-middleware-lambda < 1.7.17
- Prisma Labs graphql-playground-middleware-hapi < 1.6.13
- Prisma Labs graphql-playground-react < 1.6.24
Timeline
- 2020-06-09: disclosed: Vulnerability published via GHSA-4852-vrh7-28rf
- 2020-06-06: patched: Security fix merged to repository (commit bf1883db)
References
- https://github.com/graphql/graphql-playground/security/advisories/GHSA-4852-vrh7-28rf
- https://github.com/prisma-labs/graphql-playground/security/advisories/GHSA-4852-vrh7-28rf
- https://github.com/prisma-labs/graphql-playground/commit/bf1883db538c97b076801a60677733816cb3cfb7
- https://github.com/prisma-labs/graphql-playground