CVE-2026-63397 HIGH

CVE-2026-63397: remorses/genql code injection

Vendor Remorses
Product genql
Weakness CWE-116
Published July 16, 2026
Last update July 21, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. The malicious code is injected into the generated schema.ts file and executes when the genql client is bundled and imported.

Key dates

02Disclosure timeline

July 16, 2026 CVE published
July 21, 2026 Record updated