<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Strawberry-Graphql (0.217.0 - 0.326.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/strawberry-graphql-0.217.0---0.326.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 15:27:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/strawberry-graphql-0.217.0---0.326.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Strawberry GraphQL Permission Bypass via Awaitable Truthiness</title><link>https://feed.craftedsignal.io/briefs/2026-10-strawberry-graphql-bypass/</link><pubDate>Fri, 09 Oct 2026 15:27:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-strawberry-graphql-bypass/</guid><description>Strawberry GraphQL's PermissionExtension incorrectly handles synchronous custom permission checks that return awaitable objects, allowing unauthorized access to protected fields due to Python's truthy evaluation of unawaited coroutines.</description><content:encoded><![CDATA[<p>Strawberry GraphQL (versions 0.217.0 through 0.326.0) contains an authorization bypass vulnerability within <code>PermissionExtension.resolve()</code> in <code>strawberry/permission.py</code>. When a developer defines a custom permission class with a <code>has_permission</code> method using a standard <code>def</code> (instead of <code>async def</code>) that returns an awaitable result (such as a coroutine), the framework fails to await the result or check its resolved value. Because Python evaluates an unawaited awaitable object as truthy, the authorization check unconditionally grants access, bypassing intended security controls on the protected GraphQL field.</p>
<p>This issue affects any application using custom permission classes where <code>has_permission</code> does not return a direct boolean or utilize <code>async def</code>. Standard <code>async def</code> permissions or those returning explicit boolean values remain unaffected. The flaw impacts both <code>execute_sync()</code> and <code>execute()</code> paths for fields utilizing synchronous resolvers.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a GraphQL field protected by a custom <code>strawberry.permission.BasePermission</code> class.</li>
<li>The custom permission class is misconfigured such that <code>has_permission</code> is defined as a synchronous <code>def</code> that returns a coroutine object rather than a boolean.</li>
<li>Attacker sends a standard GraphQL query requesting data from the protected field.</li>
<li>The Strawberry GraphQL engine invokes <code>PermissionExtension.resolve()</code> during the resolution of the requested field.</li>
<li><code>PermissionExtension.resolve()</code> checks the truthiness of the returned object from <code>has_permission()</code>.</li>
<li>Python evaluates the unawaited coroutine as <code>True</code> (truthy).</li>
<li>The framework treats the authorization as granted, bypassing the logic intended to block the request.</li>
<li>The underlying field resolver is executed, and the sensitive data is returned in the GraphQL response to the attacker.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in unauthorized access to GraphQL fields intended to be protected by custom permission logic. This may lead to the exposure of sensitive data, unauthorized state changes, or the bypass of business logic checks, depending on what the specific permission-protected resolver performs. The impact is limited to applications that implement custom permission classes matching the vulnerable <code>has_permission</code> function signature.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize auditing custom permission classes within your Strawberry GraphQL implementation to identify any <code>has_permission</code> definitions that return awaitables rather than explicit boolean values.</p>
<ul>
<li>Upgrade <code>strawberry-graphql</code> to a version containing the fix for CVE-2026-107728.</li>
<li>Review all classes inheriting from <code>strawberry.permission.BasePermission</code> to ensure <code>has_permission</code> functions are either standard methods returning booleans or are explicitly defined as <code>async def</code> for asynchronous logic.</li>
<li>If using asynchronous logic, verify that the application properly utilizes <code>resolve_async()</code> or ensure all permission checks are correctly awaited before boolean evaluation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authorization-bypass</category><category>graphql</category><category>application-vulnerability</category></item></channel></rss>