Tech News
← Home  ·  All topics

Graphql

2 GoKawiil briefs on this topic

GitLab patches maximum-severity path traversal bug in commits API

GitLab issued emergency patches for CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that lets unauthenticated attackers read arbitrary files on vulnerable servers. The company also fixed a second critical bug, CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer that could let authenticated Duo Chat users steal credentials and Advanced Search configurations. Both flaws are addressed in versions 19.3.2, 19.2.6, and 19.1.

Blackstone's Beam Living app leaked SSN digits and personal data via API bug

A security researcher applying for a lease on Beam Living, a Blackstone-owned property management platform, discovered that its GraphQL API returned sensitive applicant data including partial Social Security numbers, dates of birth, credit scores, addresses and emergency contact details. The information was exposed through a network call that could be inspected by anyone with basic developer tools while submitting a rental application.