{"id":"GHSA-pfvf-fwfp-25mp","summary":"Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy","details":"### Summary\n\n`PermissionExtension.resolve()` evaluates the return value of `has_permission()` for truthiness on the synchronous path. `supports_sync` only classifies a permission as asynchronous when `has_permission` is declared with `async def` (via `inspect.iscoroutinefunction`), so a plain `def` that returns an awaitable is treated as synchronous. An awaitable is always truthy, so the check passes even when it resolves to `False` and the protected resolver runs.\n\nThe resolve path is chosen by the field resolver, not by the execution method, so any field with a synchronous resolver is affected under both `execute_sync()` and `execute()`. Permissions declared with `async def has_permission()`, or a plain `def` returning a boolean, are not affected.\n\n### Details\n\nThe affected code is `PermissionExtension.resolve()` in `strawberry/permission.py`. A permission attached to a field whose `has_permission` is a normal `def` returning an awaitable reaches this path; the awaitable is never awaited and its truthiness grants access. `resolve_async()` is not affected because it uses `await_maybe()`.\n\n### PoC\n\n```python\nimport strawberry\nfrom strawberry.permission import BasePermission\n\n\nclass DenyViaAwaitable(BasePermission):\n    message = \"denied\"\n\n    def has_permission(self, source, info, **kwargs):\n        async def result():\n            return False\n\n        return result()\n\n\n@strawberry.type\nclass Query:\n    @strawberry.field(permission_classes=[DenyViaAwaitable])\n    def secret(self) -\u003e str:\n        return \"secret\"\n\n\nschema = strawberry.Schema(Query)\nprint(schema.execute_sync(\"{ secret }\").data)  # {'secret': 'secret'} instead of a permission error\n```\n\n### Impact\n\nAn application using a custom permission whose `has_permission` is a normal `def` returning an awaitable can unintentionally grant access to the protected field. Standard permissions (a `def` returning a boolean, or an `async def`) are not affected, so exploitability depends on the application using this specific permission shape.\n\n### Fix\n\nThe synchronous path now fails closed: if `has_permission()` returns an awaitable, an error is raised instead of granting access.","aliases":["CVE-2026-107728"],"modified":"2026-10-09T14:15:05.393081289Z","published":"2026-10-09T14:07:16Z","database_specific":{"cwe_ids":["CWE-863"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-09T14:07:16Z","nvd_published_at":"2026-10-08T23:16:58Z"},"references":[{"type":"WEB","url":"https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-pfvf-fwfp-25mp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107728"},{"type":"WEB","url":"https://github.com/strawberry-graphql/strawberry/pull/4605"},{"type":"WEB","url":"https://github.com/strawberry-graphql/strawberry/commit/2ebb79796c0e5ebb43cae1abd2b5a21363b1c00e"},{"type":"PACKAGE","url":"https://github.com/strawberry-graphql/strawberry"},{"type":"WEB","url":"https://github.com/strawberry-graphql/strawberry/releases/tag/0.326.1"}],"affected":[{"package":{"name":"strawberry-graphql","ecosystem":"PyPI","purl":"pkg:pypi/strawberry-graphql"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.217.0"},{"fixed":"0.326.1"}]}],"versions":["0.217.0","0.217.1","0.218.0","0.218.0.dev1705418681","0.218.1","0.219.0","0.219.1","0.219.2","0.220.0","0.220.0.dev1709543239","0.221.0","0.221.0.dev1710955937","0.221.1","0.222.0","0.223.0","0.224.0","0.224.0.dev1711748192","0.224.1","0.224.2","0.225.0","0.225.1","0.226.0","0.226.1","0.226.2","0.227.0","0.227.0.dev1713463204","0.227.0.dev1713475585","0.227.1","0.227.2","0.227.3","0.227.4","0.227.5","0.227.6","0.227.7","0.228.0","0.228.0.dev1713643365","0.229.0","0.229.1","0.229.2","0.229.2.dev1715873118","0.229.2.dev1715881453","0.230.0","0.230.0.dev1716318708","0.231.0","0.231.1","0.232.0","0.232.1","0.232.2","0.233.0","0.233.1","0.233.2","0.233.3","0.234.0","0.234.1","0.234.2","0.234.3","0.235.0","0.235.1","0.235.1.dev1719337273","0.235.2","0.236.0","0.236.1","0.236.2","0.237.0","0.237.1","0.237.2","0.237.3","0.238.0","0.238.1","0.239.0","0.239.1","0.239.2","0.240.0","0.240.1","0.240.2","0.240.3","0.240.3.dev1726159932","0.240.4","0.241.0","0.242.0","0.243.0","0.243.1","0.244.0","0.244.1","0.245.0","0.246.0","0.246.1","0.246.2","0.246.3","0.247.0","0.247.1","0.247.2","0.248.0","0.248.1","0.249.0","0.250.0","0.250.1","0.251.0","0.252.0","0.253.0","0.253.1","0.254.0","0.254.1","0.255.0","0.256.0","0.256.1","0.257.0","0.257.0.dev1735244504","0.258.0","0.258.1","0.259.0","0.259.1","0.260.0","0.260.1","0.260.2","0.260.3","0.260.4","0.261.0","0.261.1","0.262.0","0.262.1","0.262.2","0.262.3","0.262.4","0.262.5","0.262.6","0.262.7.dev1743345593","0.263.0","0.263.0.dev1743450281","0.263.0.dev1743450503","0.263.0.dev1743450741","0.263.0.dev1743582446","0.263.1","0.263.2","0.264.0","0.264.1","0.265.0","0.265.1","0.266.0","0.266.0.dev1744797470","0.266.1","0.267.0","0.267.0.dev1746643548","0.268.0","0.268.1","0.268.2","0.268.2.dev1747436835","0.269.0","0.269.0.dev1746905409","0.269.0.dev1747164009","0.270.0","0.270.1","0.270.2","0.270.3","0.270.4","0.270.5","0.270.6","0.271.0","0.271.1","0.271.2","0.272.0","0.272.1","0.273.0","0.273.1","0.273.2","0.273.3","0.274.0","0.274.1","0.274.2","0.274.3","0.275.0","0.275.1","0.275.2","0.275.3","0.275.4","0.275.5","0.275.6","0.275.7","0.276.0","0.276.0.dev1750672223","0.276.0.dev1752831589","0.276.1","0.276.2","0.277.0","0.277.1","0.278.0","0.278.1","0.279.0","0.279.0.dev1754138688","0.279.0.dev1754156227","0.279.0.dev1754159379","0.280.0","0.281.0","0.282.0","0.283.0","0.283.1","0.283.2","0.283.3","0.284.0","0.284.1","0.284.2","0.284.3","0.284.4","0.285.0","0.285.0.dev1762469343","0.286.0","0.286.1","0.287.0","0.287.1","0.287.2","0.287.3","0.287.4","0.288.0","0.288.1","0.288.2","0.288.3","0.288.4","0.289.0","0.289.1","0.289.2","0.289.3","0.289.4","0.289.5","0.289.6","0.289.7","0.289.8","0.290.0","0.291.0","0.291.1","0.291.2","0.291.2.dev1770456508","0.291.2.dev1771437961","0.291.3","0.292.0","0.293.0","0.294.0","0.295.0","0.296.0","0.296.1","0.296.2","0.297.0","0.298.0","0.298.1","0.299.0","0.300.0","0.301.0","0.302.0","0.303.0","0.303.1","0.304.0","0.305.0","0.306.0","0.307.0","0.307.1","0.308.0","0.308.1","0.308.2","0.308.3","0.309.0","0.310.0","0.310.1","0.310.2","0.311.0","0.311.1","0.311.2","0.311.3","0.312.0","0.312.1","0.312.2","0.312.3","0.312.4","0.313.0","0.314.0","0.314.1","0.314.2","0.314.3","0.315.0","0.315.1","0.315.2","0.315.3","0.315.4","0.315.5","0.315.6","0.315.7","0.316.0","0.317.0","0.317.1","0.317.2","0.318.0","0.318.1","0.319.0","0.320.0","0.320.1","0.320.2","0.320.3","0.320.4","0.321.0","0.321.1","0.322.0","0.322.1","0.322.2","0.323.0","0.323.1","0.323.2","0.324.0","0.324.1","0.324.2","0.324.3","0.324.4","0.324.5","0.325.0","0.326.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.326.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pfvf-fwfp-25mp/GHSA-pfvf-fwfp-25mp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}