VYPR

Graphql Playground Middleware Koa

by Prisma

CVEs (1)

  • CVE-2020-4038HigJun 8, 2020
    risk 0.42cvss 7.4epss 0.07

    GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in…