graphql-python / graphql-python/graphene-django
Security report: potential findings in graphene-django
- Dominant language
- Python
- Stars
- 4.4k
- Forks
- 760
- PR merge metrics
- No merged PRs in 30d
Description
Hello maintainers,
I am opening this issue to establish vendor contact for a security review of graphene-django. The local report identifies the following potential security findings:
- IDOR in BaseDjangoFormMutation - HIGH
- IDOR in SerializerMutation - HIGH
- Mass Assignment - HIGH
- All Fields Exposed by Default - MEDIUM
- Debug Middleware SQL Leak - MEDIUM
- GraphiQL Without Auth - MEDIUM
- Template XSS - LOW
Affected version / commit tested: reported tested version; confirm with vendor
I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.
Reporter credit: logicfuzz
Contributor guide
Research direction
Start by reviewing the reported entry points: BaseDjangoFormMutation, SerializerMutation, default field exposure, debug middleware, GraphiQL, and templates. Coordinate with the maintainers through a private channel and provide the withheld reproduction notes; done means the findings are validated and a remediation path is agreed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- django, graphql, python
- Domain
- backend-api-design, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100