CVE-2023-28877: Vtex Apps-Graphql
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration data. (apps-graphql@3.x is unaffected by this issue.)
Affected products
- Vtex Apps-Graphql: version 2.x only
Published 2023-03-31. Last modified 2026-06-17.