PT-2026-3794 · Hasura · Hasura Graphql

·

CVE-2021-47748

·

Published

2026-01-21

·

Updated

2026-01-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hasura GraphQL version 1.3.3
Description Hasura GraphQL version 1.3.3 contains a remote code execution issue. Attackers can execute arbitrary shell commands through SQL query manipulation. The issue allows command injection into the run sql endpoint by crafting malicious GraphQL queries. Exploitation involves using PostgreSQL's COPY FROM PROGRAM functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47748

Affected Products

Hasura Graphql