DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107728: CVE-2026-107728: Authorization Bypass in Strawberry GraphQL Permission Validation

CVE-2026-107728: Authorization Bypass in Strawberry GraphQL Permission Validation

Vulnerability ID: CVE-2026-107728
CVSS Score: 7.5
Published: 2026-10-09

An authorization bypass vulnerability in Strawberry GraphQL between versions 0.217.0 and 0.326.1 occurs when a synchronous permission handler returns an awaitable object (such as an unawaited coroutine). Due to Python's truthiness rules, the unawaited coroutine is evaluated as True, leading to an immediate bypass of security policies.

TL;DR

Strawberry GraphQL fails to validate the return types of synchronous permission functions, allowing unawaited coroutines to evaluate as True and bypass access control.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-863
  • Attack Vector: Network
  • CVSS Score: 7.5
  • EPSS Score: 0.00353
  • EPSS Percentile: 26.95%
  • Impact: High (Confidentiality)
  • Exploit Status: Proof of Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • strawberry-graphql
  • strawberry-graphql: >= 0.217.0, < 0.326.1 (Fixed in: 0.326.1)

Code Analysis

Commit: 2ebb797

Fix permission validation bypass by preventing synchronous resolution of awaitable objects.

Mitigation Strategies

  • Upgrade strawberry-graphql to version 0.326.1 or higher.
  • Audit custom permissions to ensure synchronous has_permission functions return boolean values.
  • Use async def has_permission if invoking asynchronous operations.

Remediation Steps:

  1. Verify the installed strawberry-graphql version using pip show strawberry-graphql.
  2. Update the package using pip install --upgrade strawberry-graphql>=0.326.1.
  3. Scan codebase for BasePermission subclasses and check their return types.

References


Read the full report for CVE-2026-107728 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)