CVE-2025-31481

HIGH

API Platform Core 3.4.0-3.4.16 and 4.0.0-alpha.1-4.0.21 - Incorrect Authorization via Relay Node Type

Title source: llm
STIX 2.1

Description

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (4)
api-platform/core 4.0.0-alpha.1 - 4.0.22Packagist
api-platform/core < 3.4.17
api-platform/core >= 4.0.0, < 4.0.22
api-platform/graphql 4.0.0-alpha.1 - 4.0.22Packagist
Published Apr 03, 2025
Tracked Since Feb 18, 2026