Impact
Spring for GraphQL incorporates the GraphiQL web interface with client‑side JavaScript resources served from a public CDN without Subresource Integrity checks. An attacker who can modify the CDN content can inject malicious code that will run in the victim’s browser whenever the GraphiQL page is accessed, enabling arbitrary script execution, data theft, or further lateral movement.
Affected Systems
Spring for GraphQL versions 2.0.0 through 2.0.4, 1.4.0 through 1.4.6, 1.1.0 through 1.3.9, and 1.0.0 through 1.0.7 are affected. Deployments that expose the GraphiQL interface to users are therefore vulnerable.
Risk and Exploitability
The CVSS score of 8.1 and the EPSS score of < 1% indicate a high severity but a low exploitation probability for this vulnerability. The vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation at this time. Nevertheless, the purely client‑side attack vector potentially allows any user who visits the interface to be compromised, underscoring high risk for exposed environments.
OpenCVE Enrichment