{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astrawberrystrawberry-graphql/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:strawberry:strawberry-graphql:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-107728"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["strawberry-graphql (0.217.0 - 0.326.0)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","graphql","application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Strawberry"],"content_html":"\u003cp\u003eStrawberry GraphQL (versions 0.217.0 through 0.326.0) contains an authorization bypass vulnerability within \u003ccode\u003ePermissionExtension.resolve()\u003c/code\u003e in \u003ccode\u003estrawberry/permission.py\u003c/code\u003e. When a developer defines a custom permission class with a \u003ccode\u003ehas_permission\u003c/code\u003e method using a standard \u003ccode\u003edef\u003c/code\u003e (instead of \u003ccode\u003easync def\u003c/code\u003e) that returns an awaitable result (such as a coroutine), the framework fails to await the result or check its resolved value. Because Python evaluates an unawaited awaitable object as truthy, the authorization check unconditionally grants access, bypassing intended security controls on the protected GraphQL field.\u003c/p\u003e\n\u003cp\u003eThis issue affects any application using custom permission classes where \u003ccode\u003ehas_permission\u003c/code\u003e does not return a direct boolean or utilize \u003ccode\u003easync def\u003c/code\u003e. Standard \u003ccode\u003easync def\u003c/code\u003e permissions or those returning explicit boolean values remain unaffected. The flaw impacts both \u003ccode\u003eexecute_sync()\u003c/code\u003e and \u003ccode\u003eexecute()\u003c/code\u003e paths for fields utilizing synchronous resolvers.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a GraphQL field protected by a custom \u003ccode\u003estrawberry.permission.BasePermission\u003c/code\u003e class.\u003c/li\u003e\n\u003cli\u003eThe custom permission class is misconfigured such that \u003ccode\u003ehas_permission\u003c/code\u003e is defined as a synchronous \u003ccode\u003edef\u003c/code\u003e that returns a coroutine object rather than a boolean.\u003c/li\u003e\n\u003cli\u003eAttacker sends a standard GraphQL query requesting data from the protected field.\u003c/li\u003e\n\u003cli\u003eThe Strawberry GraphQL engine invokes \u003ccode\u003ePermissionExtension.resolve()\u003c/code\u003e during the resolution of the requested field.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ePermissionExtension.resolve()\u003c/code\u003e checks the truthiness of the returned object from \u003ccode\u003ehas_permission()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePython evaluates the unawaited coroutine as \u003ccode\u003eTrue\u003c/code\u003e (truthy).\u003c/li\u003e\n\u003cli\u003eThe framework treats the authorization as granted, bypassing the logic intended to block the request.\u003c/li\u003e\n\u003cli\u003eThe underlying field resolver is executed, and the sensitive data is returned in the GraphQL response to the attacker.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized access to GraphQL fields intended to be protected by custom permission logic. This may lead to the exposure of sensitive data, unauthorized state changes, or the bypass of business logic checks, depending on what the specific permission-protected resolver performs. The impact is limited to applications that implement custom permission classes matching the vulnerable \u003ccode\u003ehas_permission\u003c/code\u003e function signature.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize auditing custom permission classes within your Strawberry GraphQL implementation to identify any \u003ccode\u003ehas_permission\u003c/code\u003e definitions that return awaitables rather than explicit boolean values.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003estrawberry-graphql\u003c/code\u003e to a version containing the fix for CVE-2026-107728.\u003c/li\u003e\n\u003cli\u003eReview all classes inheriting from \u003ccode\u003estrawberry.permission.BasePermission\u003c/code\u003e to ensure \u003ccode\u003ehas_permission\u003c/code\u003e functions are either standard methods returning booleans or are explicitly defined as \u003ccode\u003easync def\u003c/code\u003e for asynchronous logic.\u003c/li\u003e\n\u003cli\u003eIf using asynchronous logic, verify that the application properly utilizes \u003ccode\u003eresolve_async()\u003c/code\u003e or ensure all permission checks are correctly awaited before boolean evaluation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T15:27:56Z","date_published":"2026-10-09T15:27:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-strawberry-graphql-bypass/","summary":"Strawberry GraphQL's PermissionExtension incorrectly handles synchronous custom permission checks that return awaitable objects, allowing unauthorized access to protected fields due to Python's truthy evaluation of unawaited coroutines.","title":"Strawberry GraphQL Permission Bypass via Awaitable Truthiness","url":"https://feed.craftedsignal.io/briefs/2026-10-strawberry-graphql-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:strawberry:strawberry-Graphql:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}