Executive brief
@neo4j/graphql is a library that enables GraphQL queries against Neo4j databases with built-in authentication and authorization controls. Versions prior to 7.5.6 contain an authentication bypass in the WebSocket subscription transport: attackers can forge arbitrary JWT claims without a valid signing key, allowing unauthorized access to real-time data notifications that should be restricted to authenticated users or specific roles. This leads to sensitive data leakage (e.g., real-time change notifications containing database records) accessible to any unauthenticated remote client.
Technical details
This is an authentication bypass (CWE-287) in @neo4j/graphql's GraphQL subscription handler. The vulnerability exists in versions ≥5.0.0 <5.12.14, ≥6.0.0 (unfixed, EOL), and ≥7.0.0 <7.5.6. The root cause is failure to verify the authenticity/signature of a JWT object passed through GraphQL-over-WebSocket connectionParams before using it for @authentication and @subscriptionsAuthorization directive evaluation. An unauthenticated attacker on the network can open a WebSocket connection to the GraphQL endpoint, inject a forged JWT with arbitrary claims (sub, roles, custom fields) in connectionParams.jwt, and have it accepted as a valid authenticated identity. The precondition is that the target application has subscriptions and authorization features enabled. Patches are available: upgrade to versions 7.5.6+ or 5.12.14+; v6 is end-of-life and will not be patched.
Affected products
- Neo4j @neo4j/graphql 5.0.0 to 5.12.13, 6.0.0 to 6.x (EOL), 7.0.0 to 7.5.5
Timeline
- 2026-08-06: disclosed
- 2026-08-06: patched: Versions 7.5.6 and 5.12.14 released with fix; v6 EOL, no patch