PT-2026-3794 · Hasura · Hasura Graphql

Dolev Farhi

·

Published

2026-01-21

·

Updated

2026-01-26

·

CVE-2021-47748

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hasura GraphQL version 1.3.3
Description Hasura GraphQL version 1.3.3 contains a remote code execution issue. Attackers can execute arbitrary shell commands through SQL query manipulation. The issue allows command injection into the run sql endpoint by crafting malicious GraphQL queries. Exploitation involves using PostgreSQL's COPY FROM PROGRAM functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-47748

Affected Products

Hasura Graphql