T09 · Insecure Skill Coding Practices
- Location
scripts/graphql_mapper.py:349- Finding
Graph Query Injection Through Unparameterized Query Construction
- Content
View full analysis
str: """Build WHERE clause from GraphQL where object.""" clauses = [] for key, value in where_obj.items(): if isinstance(value, dict): # Comparison operators for op, val in value.items(): if op == "eq": clauses.append(f"{key} = {val}") elif op == "gt": clauses.append(f"{key} > {val}") elif op == "lt": clauses.append(f"{key} < {val}") else: clauses.append(f"{key} = {value}") return " AND ".join(clauses) ``` ### Technical Analysis The mapper constructs executable graph query strings by directly interpolating GraphQL argument values into Cypher, Gremlin, and SPARQL syntax. No parameter binding, literal escaping, strict type validation, or backend-specific encoding is applied. The Cypher translator places an `id` inside a quoted property literal. An attacker-controlled value containing a quote can terminate that li ...[truncated 2072 chars]- Remediation
View remediation
