Medium severity5.5OSV Advisory· Published Dec 22, 2025· Updated Jun 17, 2026
CVE-2021-47714
CVE-2021-47714
Description
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3v1.0.0-alpha0, v1.0.0-alpha01, v1.0.0-alpha02, …+ 2 more
- (no CPE)range: v1.0.0-alpha0, v1.0.0-alpha01, v1.0.0-alpha02, …
- cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:*
- (no CPE)range: <=1.3.3
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/49790nvdExploit
- www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injectionnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.