api-platform/core Security Advisories (3)
-
[MEDIUM] API Platform Core does not call GraphQl securityAfterResolver
PKSA-jms4-fggn-5mmn CVE-2025-23204 GHSA-7mxx-3cgm-xxv3
Affected version: >=3.3.8,<3.3.15
Reported by:
GitHub -
[HIGH] CVE-2023-25575: Secured properties may be accessible within collections
PKSA-dsd6-6541-26zs CVE-2023-25575 GHSA-vr2x-7687-h6qv
Affected version: >=2.6.0,<2.7.10|>=3.0.0,<3.0.12|>=3.1.0,<3.1.3
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] CVE-2019-1000011: Access control bypass in GraphQL mutations
PKSA-2j74-htpf-prz8 CVE-2019-1000011 GHSA-974j-wjxx-wggj
Affected version: >=2.2.0,<2.2.10|>=2.3.0,<2.3.6
Reported by:
FriendsOfPHP/security-advisories, GitHub