CVE-2025-31481: API-Platform Core

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.

Affected products

  • API-Platform Core: from 4.0.0, before 4.0.22 (fixed in 4.0.22); before 3.4.17 (fixed in 3.4.17)

Published 2025-04-03. Last modified 2026-06-17.