CVE-2021-47714

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:*

History

27 Dec 2025, 17:15

Type Values Removed Values Added
References () https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection - Third Party Advisory, Exploit () https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 5.5

26 Dec 2025, 16:57

Type Values Removed Values Added
First Time Hasura
Hasura graphql Engine
References () https://github.com/hasura/graphql-engine - () https://github.com/hasura/graphql-engine - Product
References () https://www.exploit-db.com/exploits/49790 - () https://www.exploit-db.com/exploits/49790 - Exploit
References () https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection - () https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection - Third Party Advisory, Exploit
CPE cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:*

22 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-22 22:15

Updated : 2025-12-27 17:15


NVD link : CVE-2021-47714

Mitre link : CVE-2021-47714

CVE.ORG link : CVE-2021-47714


JSON object : View

Products Affected

hasura

  • graphql_engine
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')