๐Ÿ” CVE Alert

CVE-2021-47714

MEDIUM 5.5

Hasura GraphQL 1.3.3 Local File Read via SQL Injection

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.

CWE CWE-89
Vendor hasura
Product hasura graphql
Published Dec 22, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for hasura hasura graphql

Be the first to know when new medium vulnerabilities affecting hasura hasura graphql are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Hasura / Hasura GraphQL
1.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/49790 github.com: https://github.com/hasura/graphql-engine vulncheck.com: https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection

Credits

Dolev Farhi