Summary
A GraphQL API user with read-only permissions could actually elevate their privileges enough to write some things, for example, an attacker might be able to add new administrator accounts with credentials of their choice.
Authentication with known API credentials is required.
Common Vulnerabilities and Exposures (CVE)
Requested
GitHub Security Advisory (GHSA)
GHSA-m8mc-g8fg-4765
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
G - Green
Link to Published GHSA with More Details
Highlights
![]()