VDB
KO
HIGH 7.5

GHSA-cqmq-8755-7xvh

Keystone vulnerable to `graphql.maxTake` bypass with negative `take`

Quick fix

GHSA-cqmq-8755-7xvh — @keystone-6/core: upgrade to the fixed version with the command below.

npm install @keystone-6/core@6.5.3

Details

# Summary The value of `graphql.maxTake` can be bypassed by providing a negative input. This can be used to exceed the developer's intended `graphql.maxTake` value, allowing queries to return results in excess of the `graphql.maxTake` value set.

# Impact This affects any project relying on `graphql.maxTake` to bound the number of items returned per query.

# Patches This issue has been patched in `@keystone-6/core` version `6.5.3`.

If you cannot patch, you can workaround this by restricting `take` input values in your GraphQL queries to the bounded value, or by blocking negative values.

# Credit This issue was found by [Haxset's](https://haxset.com) Security Scanner and validated by their team.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @keystone-6/core
Introduced in: 0 Fixed in: 6.5.3
Fix npm install @keystone-6/core@6.5.3

References