CVE-2025-27407: Rmosolgo Graphql-Ruby
Critical severity, CVSS 9.0. EPSS: 3.1% chance of exploitation in the next 30 days.
graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any system which loads a schema by JSON from an untrusted source is vulnerable, including those that use GraphQL::Client to load external schemas via GraphQL introspection. Versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21 contain a patch for the issue.
Affected products
- Rmosolgo Graphql-Ruby: from 1.11.5, before 1.11.8 (fixed in 1.11.8); from 1.12.0, before 1.12.25 (fixed in 1.12.25); from 1.13.0, before 1.13.24 (fixed in 1.13.24); from 2.0.0, before 2.0.32 (fixed in 2.0.32); from 2.1.0, before 2.1.14 (fixed in 2.1.14); from 2.2.0, before 2.2.17 (fixed in 2.2.17); …
Published 2025-03-12. Last modified 2026-06-17.