PT-2025-12661 · Unknown · Api Platform Core
Published
2025-03-24
·
Updated
2025-03-24
·
CVE-2025-23204
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
API Platform Core versions 3.3.8 through 3.3.14
Description
The issue affects API Platform Core, a system for creating hypermedia-driven REST and GraphQL APIs. It involves a security check that gets called after GraphQL resolvers, which is always replaced by another one due to the lack of a break in a clause, falling back to
security. The impact is present only when there is a security check after the resolver and none inside the security check.Recommendations
For versions 3.3.8 through 3.3.14, update to version 3.3.15, which contains a patch for the issue.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Api Platform Core