CVE-2025-31481

Publication date

2025-04-03 19:20:22

Family

GitHub_M

State

PUBLISHED

Description

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.