Executive brief
Absinthe Plug is a library used to provide a GraphQL interface for Elixir web applications. A security flaw in its GraphiQL tool allows attackers to run malicious scripts in a user's browser if the user clicks a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the GraphiQL interface of absinthe_plug. The 'js_escape/1' function in 'lib/absinthe/plug/graphiql.ex' fails to escape backslashes when processing the 'query' GET parameter before embedding it into an inline JavaScript string. An attacker can use a backslash to escape the subsequent single quote (e.g., \'), breaking out of the JavaScript string context to execute arbitrary code. This vulnerability is exploitable via a crafted URL and affects versions 1.2.0 through 1.5.9. A fix is available in version 1.5.10.
Affected products
- absinthe-graphql absinthe_plug >= 1.2.0, < 1.5.10
Timeline
- 2022-10-14: disclosed: Issue first reported on GitHub
- 2026-05-08: advisory: GitHub Advisory published
- 2026-05-08: patched: Fix committed to repository