CVE-2026-63397

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. The malicious code is injected into the generated schema.ts file and executes when the genql client is bundled and imported.
Configurations

No configuration.

History

16 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 20:16

Updated : 2026-07-17 18:08


NVD link : CVE-2026-63397

Mitre link : CVE-2026-63397

CVE.ORG link : CVE-2026-63397


JSON object : View

Products Affected

No product.

CWE
CWE-116

Improper Encoding or Escaping of Output