Impact
The vulnerability allows anyone with network access to the /graphiql endpoint to open an interactive GraphiQL interface and retrieve the complete GraphQL schema without authentication. This provides a full map of available queries, mutations, types, and arguments, greatly simplifying future attacks. This is an information‑exposure weakness (CWE-200) caused by unauthenticated access and requires remediation.
Affected Systems
Applications built with nl-portal:nl.nl-portal:app versions up to and including 3.0.0 are affected. The default configuration in those versions enables both the GraphiQL playground and schema introspection, exposing the endpoint publicly. Version 3.0.1 removes these features from the default build; administrators should verify that their installations have been upgraded or, alternatively, that the corresponding configuration settings have been overridden to block unauthenticated access.
Risk and Exploitability
The EPSS score of < 1% reflects a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.3 indicates a medium level of severity. However, because the /graphiql endpoint is reachable over the network without authentication, an attacker can exploit it remotely if no additional network or application controls are in place. Applying the official fix or configuring the settings to disable the endpoint removes the risk entirely.
OpenCVE Enrichment