Junglewise Threat Intelligence

CVE-2026-42794: absinthe-graphql absinthe_plug reflected XSS in GraphiQL interface

CVE-2026-42794 · Severity: medium · CVSS 6.1 · Published 2026-05-08

Vendors: Erlang.

Executive brief

Absinthe Plug is a library used to provide a GraphQL interface for Elixir web applications. A security flaw in its GraphiQL tool allows attackers to run malicious scripts in a user's browser if the user clicks a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the GraphiQL interface of absinthe_plug. The 'js_escape/1' function in 'lib/absinthe/plug/graphiql.ex' fails to escape backslashes when processing the 'query' GET parameter before embedding it into an inline JavaScript string. An attacker can use a backslash to escape the subsequent single quote (e.g., \'), breaking out of the JavaScript string context to execute arbitrary code. This vulnerability is exploitable via a crafted URL and affects versions 1.2.0 through 1.5.9. A fix is available in version 1.5.10.

Affected products

  • absinthe-graphql absinthe_plug >= 1.2.0, < 1.5.10

Timeline

  • 2022-10-14: disclosed: Issue first reported on GitHub
  • 2026-05-08: advisory: GitHub Advisory published
  • 2026-05-08: patched: Fix committed to repository

References