CVE-2025-27407

Published Mar 12, 2025

Last updated 4 months ago

Overview

Description
graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any system which loads a schema by JSON from an untrusted source is vulnerable, including those that use GraphQL::Client to load external schemas via GraphQL introspection. Versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21 contain a patch for the issue.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-94

Social media

Hype score
Not currently trending
  1. CVE-2025-27407: Inside the Critical GraphQL-Ruby RCE Vulnerability https://t.co/GhZF3OdjzS

    @CenobeSecurity

    26 Mar 2025

    16 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Vulnerabilidad crítica en GraphQL-Ruby expone a millones a RCE ⚠️ CVE-2025-27407 (CVSS 9.1) https://t.co/bQiGulq0NV https://t.co/NBEewabta6

    @elhackernet

    18 Mar 2025

    2133 Impressions

    6 Retweets

    9 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-27407 (CVSS 9.1): Critical GraphQL-Ruby Flaw Exposes Millions to RCE https://t.co/wJH4l04HHq

    @Dinosn

    17 Mar 2025

    2194 Impressions

    5 Retweets

    12 Likes

    13 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-27407 ⚠️🔴 CRITICAL (9.1) 🏢 rmosolgo - graphql-ruby 🏗️ >= 1.11.5, < 1.11.8 🔗 https://t.co/wMPUHoRFJN 🔗 https://t.co/ozngNlvG8D 🔗 https://t.co/QbXgKYkVNx 🔗 https://t.co/hdmcKzjDha 🔗 https://t.co/blpegBWEhL 🔗 https://t.co/gKfWhWqROs #CyberCron #VulnAlert #

    @cybercronai

    14 Mar 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ Vulnerability Alert: GitLab Login Vulnerabilities 📅 Timeline: Disclosure: 2025-03-12, Patch: 2025-03-12 📌 Attribution: GitLab Security Team 🆔 cveId: CVE-2025-25291, CVE-2025-25292, CVE-2025-27407 📊 baseScore: • CVE-2025-25291: 9.8 (Critical) • CVE-2025-25292: 9.8… https:/

    @syedaquib77

    13 Mar 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Remote code execution when loading a crafted GraphQL schema (CVE-2025-27407) #CVE202527407 #GraphQL #RemoteCodeExecutionVulnerability https://t.co/Cscjvah9Pu https://t.co/NiLUMIsDn5

    @SystemTek_UK

    13 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. New post from https://t.co/uXvPWJy6tj (CVE-2025-27407 | rmosolgo graphql-ruby up to 2.3.20 Loader.load code injection (GHSA-q92j-grw3-h492)) has been published on https://t.co/AyNny46p9W

    @WolfgangSesin

    13 Mar 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. New post from https://t.co/uXvPWJy6tj (CVE-2025-27407 | rmosolgo graphql-ruby up to 2.3.20 Loader.load code injection (GHSA-q92j-grw3-h492)) has been published on https://t.co/EZwsFZFsaN

    @WolfgangSesin

    13 Mar 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. [CVE-2025-27407: CRITICAL] GraphQL-ruby, a Ruby implementation of GraphQL, had a security vulnerability allowing remote code execution before versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21.#cybersecurity,#vulnerability https://t.co/azMDq8D5zS https://t.co/s

    @CveFindCom

    12 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes