Vulnerability Database

With exploit

apollo-server

Title Severity Exploit Date Affected Version
The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutations Medium Oct 12, 2022 >= 2.0.0 < 2.25.4
Cross-site Scripting Vulnerability in GraphQL Playground (distributed by Apollo Server) High Nov 8, 2021 >= 2.0.0 < 2.25.3
>= 3.0.0 < 3.4.1
Introspection in schema validation in Apollo Server Medium Jun 5, 2020 < 2.14.2