Executive brief
GraphiQL is a web-based IDE for exploring and testing GraphQL APIs. Versions before 1.4.7 are vulnerable to cross-site scripting (XSS) attacks via malicious GraphQL type names in schema introspection responses. An attacker who can control the schema URL (through URL parameters or database values in custom implementations) can inject arbitrary JavaScript that executes in users' browsers, allowing credential theft and data exfiltration.
Technical details
This is a stored/reflected XSS vulnerability in the operation autocomplete component (onHasCompletion.ts) caused by unsafe use of the innerHTML API with unescaped GraphQL type names. The vulnerable code directly interpolates type names from GraphQL introspection responses into HTML without proper escaping. An attacker must either compromise the HTTP schema introspection response or control the schema URL parameter in custom GraphiQL implementations. The attack surface is significantly larger when the schema URL is user-controllable (e.g., via ?endpoint= query parameter), enabling phishing attacks. The fix (graphiql@1.4.7) implements defense-in-depth: HTML-escaping type names, schema validation against the GraphQL specification, and updated markdown-it library for safe HTML rendering.
Affected products
- GraphQL GraphiQL 0.5.0 to 1.4.6
Timeline
- 2021-11-08: disclosed
- 2021-11-08: patched: graphiql@1.4.7 released