How to use this reference
The maintainer identifies versions 2.5.23 through 2.6.5 as affected and 2.6.6 as patched. Only the newer Execution::Next mode and resolver-thrown authorization errors are implicated; other authorization forms worked correctly. Editorial lesson: preserve denial semantics across execution engines and keep error formatting separate from authority to execute.
Before reading
- Basic API access-control concepts
- Familiarity with server-side data processing
Context and limits
- The research reports testing 2.6.5 and reproducing the behavior on 2.6.1. Its fixture demonstrates resolver execution and returned data; database deletion, external calls and broader privilege escalation are possible application-dependent consequences, not demonstrated production incidents.
- The application must use the affected execution mode and deny access by raising the relevant authorization exception. This is not a claim that all GraphQL-Ruby deployments bypassed authorization.
- Research timeline: reported July 16, acknowledged and fixed July 17, 2026. Maintainer advisory and patched release date are July 21; detailed research publication is August 8.
- No CVE is identified in the maintainer advisory. Discovery is credited to GitHub Security Lab Taskflow Agent with manual verification; Bas Alberts is the research byline. No patch reproduction was performed.
Sources and provenance
- GHSL-2026-152: Privilege escalation via authorization bypass in graphql-ruby GitHub Security Lab · reviewed 2026-10-03
- Authorization Bypass in Execution::Next GraphQL-Ruby · reviewed 2026-10-03
- GraphQL-Ruby 2.6.6 changelog GraphQL-Ruby · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.