{"id":"GHSA-5c7w-4wm3-85vw","summary":"@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection","details":"## Finding\n\n**Location**: `core/src/client/graphql.ts:66-80`\n\nThe `gql` template tag function warned about interpolated values containing GraphQL metacharacters (`{}():`) but still concatenated them into the query string, enabling potential GraphQL injection.\n\n## Status\n\n**Fixed in v0.2.136** — The `gql` function now throws an error when metacharacters are detected in interpolated values, forcing developers to use the `variables` parameter.","modified":"2026-09-10T03:51:10.446887808Z","published":"2026-07-02T19:00:12Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-02T19:00:12Z","nvd_published_at":null,"cwe_ids":["CWE-943"]},"references":[{"type":"WEB","url":"https://github.com/asymmetric-effort/specifyjs/security/advisories/GHSA-5c7w-4wm3-85vw"},{"type":"WEB","url":"https://github.com/asymmetric-effort/specifyjs/commit/25d1fb491d99479efdf501f5f75e0bb80c908f0a"},{"type":"PACKAGE","url":"https://github.com/asymmetric-effort/specifyjs"}],"affected":[{"package":{"name":"@asymmetric-effort/specifyjs","ecosystem":"npm","purl":"pkg:npm/%40asymmetric-effort/specifyjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.2.136"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-5c7w-4wm3-85vw/GHSA-5c7w-4wm3-85vw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}