Executive brief
Spring for GraphQL bundles a GraphiQL interactive IDE that can be accessed through a web browser. An attacker can craft a malicious URL that, when clicked by a victim, causes the victim's browser to send authenticated requests to the application's GraphQL endpoints, potentially exposing confidential data to the attacker. This could lead to unauthorized access to sensitive business information.
Technical details
The vulnerability is a cross-site request forgery (CSRF) issue affecting the GraphiQL page bundled with Spring for GraphQL. The GraphiQL interface sends unauthenticated or cross-origin requests to the application's GraphQL endpoints without proper CSRF protections. An attacker can craft a malicious URL containing a GraphQL query and, through social engineering, trick a user into clicking it while authenticated to the application. The victim's browser will execute the query in the context of their authentication session, allowing the attacker to retrieve sensitive data. Affected versions include Spring for GraphQL 1.0.0–1.0.7, 1.1.0–1.3.9, 1.4.0–1.4.6, and 2.0.0–2.0.4. Patches are available in newer versions.
Affected products
- Spring Spring for GraphQL 1.0.0 through 1.0.7, 1.1.0 through 1.3.9, 1.4.0 through 1.4.6, 2.0.0 through 2.0.4
Timeline
- 2026-08-27: disclosed