absinthe-graphql CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

absinthe-graphql vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to absinthe-graphql, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-42794 Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripting via the GraphiQL interface. 'Elixir.Absinthe.Plug.GraphiQL':js_escape/1 in lib/absinthe/plug/graphiql.ex escapes single quotes and newlines in the query GET parameter before embedding it in an inline JavaScript string, but does not escape backslashes. An attacker can bypass the escaping by prefixing a quote with a backslash (e.g. \'), breaking o 6b3ad84c-e1a6-4bf7-a703-f496b71e49db 2.3 0.01% 2026-05-08 2026-05-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence