Junglewise Threat Intelligence

GraphQL Armor Cost-Limit Plugin Bypass via Introspection Query Obfuscation

Severity: low · CVSS 3 · Published 2025-04-25

Vendors: npm.

Executive brief

GraphQL Armor is a security plugin that restricts GraphQL query complexity via cost-limiting to prevent denial-of-service attacks. When the introspection-ignore feature is enabled (the default), attackers can bypass cost limits by naming queries or fragments "__schema", allowing them to send expensive queries that exhaust server resources.

Technical details

The vulnerability is a logic error in the cost-limit plugin's introspection-bypass check. The computeComplexity function attempts to skip cost calculation for introspection queries by checking if a node's name equals "__schema", but fails to validate the node type. Since nodes can be FieldNode, FragmentDefinitionNode, OperationDefinitionNode, or others, attackers can bypass the check by naming a query or fragment "__schema" instead of using the "__schema" field, causing cost calculation to be skipped entirely. The fix restricts the check to FieldNode types only. No authentication is required; the vulnerability is exploitable by any unauthenticated network client sending a crafted GraphQL query. Fixed in version 2.4.2.

Affected products

  • Escape Technologies graphql-armor-cost-limit <= 2.4.0

Timeline

  • 2025-04-25: disclosed
  • 2025-04-25: patched: Fixed in version 2.4.2

References