CVE-2023-28877: Vtex Apps-Graphql

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration data. (apps-graphql@3.x is unaffected by this issue.)

Affected products

  • Vtex Apps-Graphql: version 2.x only

Published 2023-03-31. Last modified 2026-06-17.