Description


Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.

Related CPE's


Could not find any relations

Weaknesses



CWE-89

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

6.8 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Received

Published

2025-12-22T22:15:58.933

9 hours ago

Last modified

2025-12-22T22:15:58.933

9 hours ago