strawberry-graphql is vulnerable to Information Disclosure
40
Medium Risk
Affected versions of this package are affected by an insecure validation when handling objects from integrations such as Django, SQLAlchemy, or Pydantic. When these objects are received in a format that closely resembles the expected type, it can result in is_type_of checks incorrectly identifying the type. An attacker could exploit this misclassification to force the application to return critical data, resulting in Information Disclosure.
You are affected if you are using a version that falls within the vulnerable range.
strawberry-graphql is vulnerable to Information Disclosure in versions 0.43.0 - 0.256.1.
Upgrade the strawberry-graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant