Skip to content

Security report: potential findings in graphene-django #1561

Description

@leeyu44

Hello maintainers,

I am opening this issue to establish vendor contact for a security review of graphene-django. The local report identifies the following potential security findings:

  • IDOR in BaseDjangoFormMutation - HIGH
  • IDOR in SerializerMutation - HIGH
  • Mass Assignment - HIGH
  • All Fields Exposed by Default - MEDIUM
  • Debug Middleware SQL Leak - MEDIUM
  • GraphiQL Without Auth - MEDIUM
  • Template XSS - LOW

Affected version / commit tested: reported tested version; confirm with vendor

I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.

Reporter credit: logicfuzz

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions