Hello maintainers,
I am opening this issue to establish vendor contact for a security review of graphene-django. The local report identifies the following potential security findings:
- IDOR in BaseDjangoFormMutation - HIGH
- IDOR in SerializerMutation - HIGH
- Mass Assignment - HIGH
- All Fields Exposed by Default - MEDIUM
- Debug Middleware SQL Leak - MEDIUM
- GraphiQL Without Auth - MEDIUM
- Template XSS - LOW
Affected version / commit tested: reported tested version; confirm with vendor
I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.
Reporter credit: logicfuzz
Hello maintainers,
I am opening this issue to establish vendor contact for a security review of graphene-django. The local report identifies the following potential security findings:
Affected version / commit tested: reported tested version; confirm with vendor
I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.
Reporter credit: logicfuzz