Authentication Bypass by Assumed-Immutable Data Affecting @neo4j/graphql package, versions >=5.0.0 <5.12.14>=6.0.0 <7.5.6


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-NEO4JGRAPHQL-18592356
  • published8 Aug 2026
  • disclosed6 Aug 2026
  • creditUnknown

Introduced: 6 Aug 2026

NewCVE-2026-5423  (opens in a new tab)
CWE-302  (opens in a new tab)

How to fix?

Upgrade @neo4j/graphql to version 5.12.14, 7.5.6 or higher.

Overview

@neo4j/graphql is an A GraphQL to Cypher query execution layer for Neo4j and JavaScript GraphQL implementations

Affected versions of this package are vulnerable to Authentication Bypass by Assumed-Immutable Data in the connectionParams.jwt process. An attacker can gain unauthorized access to subscription events by supplying a forged JWT object through a GraphQL-over-WebSocket connection.

CVSS Base Scores

version 4.0
version 3.1