HACKERONE

Enjin: Unauthenticated GraphQL access by prepending __schema to private operations_H1:3452015

Description

A security vulnerability was identified in the GraphQL schema of the Enjin Platform. The vulnerability allowed unauthorized access to the GraphQL schema by prepending "__schema" to private operations. The vulnerability was discovered and reported by a security researcher. The specific location of the vulnerability within the platform-core repository was identified, and a fix was subsequently implemented to address the issue.
Visit Original Source

Basic Information

ID H1:3452015
Published Dec 4, 2025 at 20:09
Modified Dec 5, 2025 at 15:10

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.