Junglewise Threat Intelligence

CVE-2021-41249: GraphQL Playground reflected XSS via schema introspection

CVE-2021-41249 · Severity: low · CVSS 3.1 · Published 2021-11-08

Vendors: npm.

Executive brief

GraphQL Playground is a web-based IDE used by developers to explore and test GraphQL APIs. A reflected XSS vulnerability allows attackers to inject malicious JavaScript by crafting a link with a malicious GraphQL endpoint URL. When a user clicks the link, arbitrary code executes in their browser, enabling credential theft or other attacks without the user realizing they've visited a compromised site.

Technical details

The vulnerability is a stored/reflected XSS flaw in graphql-playground-react's schema introspection handling. The root cause is unsafe use of the innerHTML API when interpolating GraphQL type names directly into HTML without proper escaping. When a user loads a GraphQL schema (via endpoint query parameter or prop), malicious type names containing JavaScript payloads are rendered unsanitized. The attack is triggered during operation autocomplete when the user begins typing in the query editor. Exploitation requires user interaction (clicking a malicious link and typing in the editor) and no authentication. The patch (v1.7.28) implements defense in depth: HTML-escaping of type names, schema validation against the GraphQL spec, and migration away from the unsafe "marked" library to markdown-it for Markdown rendering. Systems using graphql-playground-html or middleware packages that do not pin a specific version are automatically patched via CDN; pinned versions and Apollo Server deployments require manual updates.

Affected products

  • GraphQL graphql-playground-react < 1.7.28
  • GraphQL graphql-playground < 1.7.28
  • GraphQL graphql-playground-html versions with pinned graphql-playground-react < 1.7.28
  • GraphQL graphql-playground-express versions with pinned graphql-playground-react < 1.7.28
  • GraphQL graphql-playground-middleware-koa versions with pinned graphql-playground-react < 1.7.28
  • GraphQL graphql-playground-middleware-hapi versions with pinned graphql-playground-react < 1.7.28
  • GraphQL graphql-playground-middleware-lambda versions with pinned graphql-playground-react < 1.7.28

Timeline

  • 2021-11-04: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-59r9-6jp6-jcm7
  • 2021-11-08: advisory: OSV database publication
  • 2021-11-04: patched: Patch released as graphql-playground-react@1.7.28

References