Impact
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the checkUserPassword GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied password values are interpolated directly into a DQL checkpwd() query via fmt.Sprintf without any escaping or parameterization. An attacker can inject a password containing a double-quote character to break out of the DQL string literal and append arbitrary DQL query blocks. Version 25.3.4 patches the issue.
Affected Systems
All instances of dgraph‑io dgraph running a version earlier than 25.3.4 are affected, as the vulnerability exists in the GraphQL API used for user authentication.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is reported as indicating a very low but nonzero exploitation probability. The issue is not listed in the CISA KEV catalog, which suggests no confirmed public exploits yet. Based on the description, it is inferred that the GraphQL endpoint requires authentication, so attackers must first compromise credentials or gain client access. Once inside, the flaw can be leveraged to run arbitrary DQL, making the risk significant for systems where sensitive data resides. This vulnerability represents a CWE-943 weakness, indicating lack of input validation for externally supplied data.
OpenCVE Enrichment
Github GHSA