PT-2025-12661 · Unknown · Api Platform Core

Published

2025-03-24

·

Updated

2025-03-24

·

CVE-2025-23204

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions API Platform Core versions 3.3.8 through 3.3.14
Description The issue affects API Platform Core, a system for creating hypermedia-driven REST and GraphQL APIs. It involves a security check that gets called after GraphQL resolvers, which is always replaced by another one due to the lack of a break in a clause, falling back to security. The impact is present only when there is a security check after the resolver and none inside the security check.
Recommendations For versions 3.3.8 through 3.3.14, update to version 3.3.15, which contains a patch for the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-23204
GHSA-7MXX-3CGM-XXV3

Affected Products

Api Platform Core