Impact
The vulnerability occurs in the GraphiQL interface bundled with Spring for GraphQL. A crafted URL can cause a victim’s browser to send GraphQL requests that may expose confidential data to an attacker’s domain. This results in information disclosure and compromises confidentiality of data accessed by the GraphQL endpoints.
Affected Systems
The issue affects Spring for GraphQL. Supported products are: Spring:Spring for GraphQL. Affected releases include 2.0.0‑2.0.4, 1.4.0‑1.4.6, 1.1.0‑1.3.9, and 1.0.0‑1.0.7. If your application uses any of these versions, it is vulnerable.
Risk and Exploitability
The CVSS score is not provided in the public data, and that the EPSS score is not available, so the published exploitation probability cannot be quantified. The vulnerability is listed as not in the CISA KEV catalog, indicating no confirmed widespread exploitation cases yet. Nevertheless, the attack vector is inferred to be a direct example of an attacker distributing a malicious link that a victim may click, leading to browser‑initiated requests to internal GraphQL endpoints. Because the leak depends on the victim opening a link, the risk is limited to users who are exposed to the crafted URL, but the potential loss of confidential information is significant.
OpenCVE Enrichment