CVE-2026-107728: Authorization Bypass in Strawberry GraphQL Permission Validation
Vulnerability ID: CVE-2026-107728
CVSS Score: 7.5
Published: 2026-10-09
An authorization bypass vulnerability in Strawberry GraphQL between versions 0.217.0 and 0.326.1 occurs when a synchronous permission handler returns an awaitable object (such as an unawaited coroutine). Due to Python's truthiness rules, the unawaited coroutine is evaluated as True, leading to an immediate bypass of security policies.
TL;DR
Strawberry GraphQL fails to validate the return types of synchronous permission functions, allowing unawaited coroutines to evaluate as True and bypass access control.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-863
- Attack Vector: Network
- CVSS Score: 7.5
- EPSS Score: 0.00353
- EPSS Percentile: 26.95%
- Impact: High (Confidentiality)
- Exploit Status: Proof of Concept
- CISA KEV Status: Not Listed
Affected Systems
- strawberry-graphql
-
strawberry-graphql: >= 0.217.0, < 0.326.1 (Fixed in:
0.326.1)
Code Analysis
Commit: 2ebb797
Fix permission validation bypass by preventing synchronous resolution of awaitable objects.
Mitigation Strategies
- Upgrade strawberry-graphql to version 0.326.1 or higher.
- Audit custom permissions to ensure synchronous has_permission functions return boolean values.
- Use async def has_permission if invoking asynchronous operations.
Remediation Steps:
- Verify the installed strawberry-graphql version using pip show strawberry-graphql.
- Update the package using pip install --upgrade strawberry-graphql>=0.326.1.
- Scan codebase for BasePermission subclasses and check their return types.
References
- GitHub Security Advisory GHSA-pfvf-fwfp-25mp
- Fix PR #4605
- Fixing Commit
- Release 0.326.1
- NVD - CVE-2026-107728
- CVE-2026-107728
Read the full report for CVE-2026-107728 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)