CVE-2022-36084
cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to inject arbitrary AQL queries that will be forwarded to and executed by ArangoDB. Schemas that do not use `@flexSearchFulltext` are not affected. The attacker needs to have `READ` permission to at least one root entity type that has `@flexSearchFulltext` enabled. The issue has been fixed in version 3.0.2 and in version 2.7.0 of cruddl. As a workaround, users can temporarily remove `@flexSearchFulltext` from their schemas.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.03%
- CWE
- CWE-943, CWE-74
- Published
- 2022-09-08
- Last modified
- 2026-03-13
Affected products
- AEB-labs cruddl
- AEB-labs cruddl
Weakness type
Related vulnerabilities
- CVE-2024-4872 — A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an
- CVE-2020-36195 — SQL Injection Vulnerability in Multimedia Console and the Media Streaming Add-On
- CVE-2026-32248 — Parse Server: Account takeover via operator injection in authentication data identifier
- CVE-2026-30941 — Parse Server has a NoSQL injection via token type in password reset and email verification endpoints
- CVE-2026-25514 — FacturaScripts has SQL Injection vulnerability in Autocomplete Actions
- CVE-2025-24787 — Parameter injection in DB connection URIs leading to local file inclusion in WhoDB
- CVE-2026-54350 — Budibase: Anonymous NoSQL operator injection via published-app query templates
- CVE-2026-33980 — Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries