vulns.co
/
GKData.io MCP

GitHub Security Lab · 1 min read

GraphQL-Ruby: authorization exceptions must stop execution

A GraphQL-Ruby execution-engine path converted a resolver authorization exception into permission to continue. Research demonstrates a denied resolver running and returning a fixture value, while the legacy engine stopped it. This illustrates why error handling must preserve the security meaning of a denial.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

The maintainer identifies versions 2.5.23 through 2.6.5 as affected and 2.6.6 as patched. Only the newer Execution::Next mode and resolver-thrown authorization errors are implicated; other authorization forms worked correctly. Editorial lesson: preserve denial semantics across execution engines and keep error formatting separate from authority to execute.

Before reading

  • Basic API access-control concepts
  • Familiarity with server-side data processing

Context and limits

  • The research reports testing 2.6.5 and reproducing the behavior on 2.6.1. Its fixture demonstrates resolver execution and returned data; database deletion, external calls and broader privilege escalation are possible application-dependent consequences, not demonstrated production incidents.
  • The application must use the affected execution mode and deny access by raising the relevant authorization exception. This is not a claim that all GraphQL-Ruby deployments bypassed authorization.
  • Research timeline: reported July 16, acknowledged and fixed July 17, 2026. Maintainer advisory and patched release date are July 21; detailed research publication is August 8.
  • No CVE is identified in the maintainer advisory. Discovery is credited to GitHub Security Lab Taskflow Agent with manual verification; Bas Alberts is the research byline. No patch reproduction was performed.

Sources and provenance

  1. GHSL-2026-152: Privilege escalation via authorization bypass in graphql-ruby GitHub Security Lab · reviewed 2026-10-03
  2. Authorization Bypass in Execution::Next GraphQL-Ruby · reviewed 2026-10-03
  3. GraphQL-Ruby 2.6.6 changelog GraphQL-Ruby · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software