CRITICAL🇵🇱 Wersja polska

CVE-2021-47748

CVSS 9.3v4.0pub. 2026-01-21upd. 2026-02-02

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM functionality.

🤖 AI Analysis
How it works

An attacker sends a crafted GraphQL query to the run_sql endpoint, injecting malicious system commands (command injection). The attack mechanism exploits PostgreSQL functionality called COPY FROM PROGRAM, which allows execution of system shell commands directly from an SQL query. By appropriately manipulating the SQL query passed to this endpoint, an attacker can achieve full code execution on the target server.

Impact

An attacker can execute arbitrary system commands on the server hosting Hasura GraphQL Engine, leading to complete system compromise, data exfiltration, and potential lateral movement within the internal network.

Mitigation & patch

Apply patches available from the vendor according to the references provided. Additionally, it is recommended to restrict access to the run_sql endpoint exclusively to trusted, authenticated users and implement appropriate firewall rules blocking unauthorized access to the GraphQL interface.

Who is affected

Hasura GraphQL Engine version 1.3.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Hasura Graphql Engine

    APP
    Hasura
    1.3.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLiCommand Injection
CWE
References

Related vulnerabilities

CVE-2021-47713HIGH8.7same product

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service...

CVE-2023-27588HIGH7.5same product

Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has ...

CVE-2022-46792HIGH8.8same product

Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres bac...

CVE-2019-1020015HIGH7.5same product

graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying J...

CVE-2026-54698MEDIUM6.0same product

Hasura to produkt open-source oferujący użytkownikom GraphQL lub REST API. Przed wersjami 2.49.2 i 2.45.5 użyt...