graphql-python / graphql-python/graphene-django

Security report: potential findings in graphene-django

Open
#1,561 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
4.4k
Forks
760
PR merge metrics
No merged PRs in 30d

Description

Hello maintainers,

I am opening this issue to establish vendor contact for a security review of graphene-django. The local report identifies the following potential security findings:

- IDOR in BaseDjangoFormMutation - HIGH
- IDOR in SerializerMutation - HIGH
- Mass Assignment - HIGH
- All Fields Exposed by Default - MEDIUM
- Debug Middleware SQL Leak - MEDIUM
- GraphiQL Without Auth - MEDIUM
- Template XSS - LOW

Affected version / commit tested: reported tested version; confirm with vendor

I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.

Reporter credit: logicfuzz

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the reported entry points: BaseDjangoFormMutation, SerializerMutation, default field exposure, debug middleware, GraphiQL, and templates. Coordinate with the maintainers through a private channel and provide the withheld reproduction notes; done means the findings are validated and a remediation path is agreed.

Written by the indexing model from the issue text.

Assessment

Tech stack
django, graphql, python
Domain
backend-api-design, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.