SCA: security update for strawberry-graphql (GHSA-pfvf-fwfp-25mp)

high Tenable Cloud Security Plugin ID 474042

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Strawberry GraphQL is a library for creating GraphQL APIs. From 0.217.0 until 0.326.1,
PermissionExtension.resolve() on a synchronous field resolver evaluates the result of has_permission() for
truthiness. When a custom permission declares has_permission() as a normal function but returns an
awaitable, supports_sync does not classify it as asynchronous, the awaitable is not awaited, and its
inherently truthy object value permits the protected resolver to run even when the result would resolve to
false. This affects synchronous field resolvers under both execute_sync() and execute(); permissions
declared with async def has_permission() and synchronous permissions returning a boolean are not affected.
This issue is fixed in version 0.326.1. (CVE-2026-107728)

Solution

Update the strawberry-graphql library and its related packages to version 0.326.1 or later.

See Also

https://github.com/advisories/GHSA-pfvf-fwfp-25mp

Plugin Details

Severity: High

ID: 474042

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.17

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-107728

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/8/2026

Reference Information

CVE: CVE-2026-107728

cwe: CWE-863