GraphQL Tools Vulnerability in Utilities from Ardatan
CVE-2026-104852

8.2HIGH

Key Information:

Vendor

Ardatan

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104852?

The GraphQL Tools utils package prior to version 12.0.1 contains a vulnerability in the mergeDeep function, which improperly handles inherited properties during the merging of source objects. Specifically, it fails to exclude prototype keys like proto, constructor, or prototype. This flaw allows an unauthenticated GraphQL client to manipulate field names, leading to collisions in responses from different subgraphs. Consequently, this can result in overwriting the Function.prototype.call property with values from subgraphs, disrupting subsequent requests and requiring a system restart. Users are advised to upgrade to version 12.0.1 to mitigate this issue.

Affected Version(s)

graphql-tools < 12.0.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.