CVE-2025-27407

Published Mar 12, 2025

Last updated 23 days ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-27407 is a vulnerability in graphql-ruby, a Ruby implementation of GraphQL. It affects versions starting from 1.11.5 and prior to 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21. The vulnerability stems from the way graphql-ruby handles schema loading via `GraphQL::Schema.from_introspection` and `GraphQL::Schema::Loader.load`. Loading a malicious schema definition can result in remote code execution. Systems that load schemas by JSON from untrusted sources are particularly vulnerable, including those using GraphQL::Client to load external schemas via GraphQL introspection.

Description
graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any system which loads a schema by JSON from an untrusted source is vulnerable, including those that use GraphQL::Client to load external schemas via GraphQL introspection. Versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21 contain a patch for the issue.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-94

Social media

Hype score
Not currently trending
  1. CVE-2025-27407: Inside the Critical GraphQL-Ruby RCE Vulnerability https://t.co/GhZF3OdjzS

    @CenobeSecurity

    26 Mar 2025

    16 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Vulnerabilidad crítica en GraphQL-Ruby expone a millones a RCE ⚠️ CVE-2025-27407 (CVSS 9.1) https://t.co/bQiGulq0NV https://t.co/NBEewabta6

    @elhackernet

    18 Mar 2025

    2133 Impressions

    6 Retweets

    9 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-27407 (CVSS 9.1): Critical GraphQL-Ruby Flaw Exposes Millions to RCE https://t.co/wJH4l04HHq

    @Dinosn

    17 Mar 2025

    2194 Impressions

    5 Retweets

    12 Likes

    13 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-27407 βš οΈπŸ”΄ CRITICAL (9.1) 🏒 rmosolgo - graphql-ruby πŸ—οΈ >= 1.11.5, < 1.11.8 πŸ”— https://t.co/wMPUHoRFJN πŸ”— https://t.co/ozngNlvG8D πŸ”— https://t.co/QbXgKYkVNx πŸ”— https://t.co/hdmcKzjDha πŸ”— https://t.co/blpegBWEhL πŸ”— https://t.co/gKfWhWqROs #CyberCron #VulnAlert #

    @cybercronai

    14 Mar 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ Vulnerability Alert: GitLab Login Vulnerabilities πŸ“… Timeline: Disclosure: 2025-03-12, Patch: 2025-03-12 πŸ“Œ Attribution: GitLab Security Team πŸ†” cveId: CVE-2025-25291, CVE-2025-25292, CVE-2025-27407 πŸ“Š baseScore: β€’ CVE-2025-25291: 9.8 (Critical) β€’ CVE-2025-25292: 9.8… https:/

    @syedaquib77

    13 Mar 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Remote code execution when loading a crafted GraphQL schema (CVE-2025-27407) #CVE202527407 #GraphQL #RemoteCodeExecutionVulnerability https://t.co/Cscjvah9Pu https://t.co/NiLUMIsDn5

    @SystemTek_UK

    13 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. New post from https://t.co/uXvPWJy6tj (CVE-2025-27407 | rmosolgo graphql-ruby up to 2.3.20 Loader.load code injection (GHSA-q92j-grw3-h492)) has been published on https://t.co/EZwsFZFsaN

    @WolfgangSesin

    13 Mar 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. New post from https://t.co/uXvPWJy6tj (CVE-2025-27407 | rmosolgo graphql-ruby up to 2.3.20 Loader.load code injection (GHSA-q92j-grw3-h492)) has been published on https://t.co/AyNny46p9W

    @WolfgangSesin

    13 Mar 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. [CVE-2025-27407: CRITICAL] GraphQL-ruby, a Ruby implementation of GraphQL, had a security vulnerability allowing remote code execution before versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21.#cybersecurity,#vulnerability https://t.co/azMDq8D5zS https://t.co/s

    @CveFindCom

    12 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes