GraphQL Tools Vulnerability in Utilities from Ardatan
CVE-2026-104852
8.2HIGH
What is CVE-2026-104852?
The GraphQL Tools utils package prior to version 12.0.1 contains a vulnerability in the mergeDeep function, which improperly handles inherited properties during the merging of source objects. Specifically, it fails to exclude prototype keys like proto, constructor, or prototype. This flaw allows an unauthenticated GraphQL client to manipulate field names, leading to collisions in responses from different subgraphs. Consequently, this can result in overwriting the Function.prototype.call property with values from subgraphs, disrupting subsequent requests and requiring a system restart. Users are advised to upgrade to version 12.0.1 to mitigate this issue.
Affected Version(s)
graphql-tools < 12.0.1
