GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the associated dependent middleware packages are also affected including but not limited to graphql-playground-middleware-express before version 1.7.16, graphql-playground-middleware-koa before version 1.6.15, graphql-playground-middleware-lambda before version 1.7.17, and graphql-playground-middleware-hapi before 1.6.13.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4852-vrh7-28rf Reflected XSS in GraphQL Playground
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T07:52:20.823Z

Reserved: 2019-12-30T00:00:00

Link: CVE-2020-4038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-08T21:15:09.923

Modified: 2024-11-21T05:32:11.997

Link: CVE-2020-4038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses