{"id":"CVE-2021-47714","details":"Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.","modified":"2026-08-07T17:03:18.807403Z","published":"2025-12-22T22:15:58.933Z","references":[{"type":"PACKAGE","url":"https://github.com/hasura/graphql-engine"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/49790"},{"type":"EVIDENCE","url":"https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hasura/graphql-engine","events":[{"introduced":"8c9ffbeb6d60226970f69b6ef5b08d9551d944e2"},{"last_affected":"8c9ffbeb6d60226970f69b6ef5b08d9551d944e2"}],"database_specific":{"cpe":"cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.3.3"},{"last_affected":"1.3.3"}],"source":"CPE_STRING"}}],"versions":["1.3.3","v1.3.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47714.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}