CVE-2025-31481

HIGH

Api-platform Graphql < 4.0.22 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (4)
api-platform/core 4.0.0-alpha.1 - 4.0.22Packagist
api-platform/core < 3.4.17
api-platform/core >= 4.0.0, < 4.0.22
api-platform/graphql 4.0.0-alpha.1 - 4.0.22Packagist
Published Apr 03, 2025
Tracked Since Feb 18, 2026