Description
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Dolev Farhi
References
www.exploit-db.com/exploits/49790 (ExploitDB-49790)
github.com/hasura/graphql-engine (Hasura GraphQL Engine GitHub Repository)
www.vulncheck.com/...aphql-local-file-read-via-sql-injection (VulnCheck Advisory: Hasura GraphQL 1.3.3 Local File Read via SQL Injection)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.