From be85f3776f2546362e4743fa26693d4cfcaadddb Mon Sep 17 00:00:00 2001 From: "Abdullah." <125115953+mabdullahabaid@users.noreply.github.com> Date: Wed, 22 Oct 2025 19:07:47 +0500 Subject: [PATCH] fix: graphql uncontrolled resource consumption vulnerability (#15260) Fixes [Dependabot Alert 73](https://github.com/twentyhq/twenty/security/dependabot/73) - graphql uncontrolled resource consumption vulnerability. Updated the patch version - from 16.8.0 to 16.8.1 - and this patch only touches the issue identified by the alert.

image

Manually tested a few mutations, ran test cases, and everything seems to work fine. Not expecting it to break anything. Two files changed in the original patch fix: https://github.com/graphql/graphql-js/commit/8f4c64eb6a7112a929ffeef00caa67529b3f2fcf --- package.json | 2 +- packages/twenty-front/package.json | 2 +- packages/twenty-server/package.json | 2 +- yarn.lock | 12 ++++++------ 4 files changed, 9 insertions(+), 9 deletions(-) diff --git a/package.json b/package.json index 731ee556c0..5f7882dd61 100644 --- a/package.json +++ b/package.json @@ -217,7 +217,7 @@ "name": "twenty", "packageManager": "yarn@4.9.2", "resolutions": { - "graphql": "16.8.0", + "graphql": "16.8.1", "type-fest": "4.10.1", "typescript": "5.9.2", "graphql-redis-subscriptions/ioredis": "^5.6.0", diff --git a/packages/twenty-front/package.json b/packages/twenty-front/package.json index b35f3fb435..ac578ad86b 100644 --- a/packages/twenty-front/package.json +++ b/packages/twenty-front/package.json @@ -78,7 +78,7 @@ "docx": "^9.1.0", "file-saver": "^2.0.5", "graphiql": "^3.1.1", - "graphql": "^16.8.0", + "graphql": "16.8.1", "graphql-sse": "^2.5.4", "input-otp": "^1.4.2", "js-cookie": "^3.0.5", diff --git a/packages/twenty-server/package.json b/packages/twenty-server/package.json index 053cc10609..6d61f748b7 100644 --- a/packages/twenty-server/package.json +++ b/packages/twenty-server/package.json @@ -104,7 +104,7 @@ "glob": "11.0.1", "google-auth-library": "8.9.0", "googleapis": "105.0.0", - "graphql": "16.8.0", + "graphql": "16.8.1", "graphql-fields": "2.0.3", "graphql-middleware": "^6.1.35", "graphql-rate-limit": "3.3.0", diff --git a/yarn.lock b/yarn.lock index badc218105..4435b8c12e 100644 --- a/yarn.lock +++ b/yarn.lock @@ -34874,10 +34874,10 @@ __metadata: languageName: node linkType: hard -"graphql@npm:16.8.0": - version: 16.8.0 - resolution: "graphql@npm:16.8.0" - checksum: 10c0/f7ca0302e8d658012db90b428ec66c1453afe53fbffa21404a28b5bdec5b0e88641d38416ef3d582acad7ddde2effe729e2b050a1483a2e9d4a6111e892e4903 +"graphql@npm:16.8.1": + version: 16.8.1 + resolution: "graphql@npm:16.8.1" + checksum: 10c0/129c318156b466f440914de80dbf7bc67d17f776f2a088a40cb0da611d19a97c224b1c6d2b13cbcbc6e5776e45ed7468b8432f9c3536724e079b44f1a3d57a8a languageName: node linkType: hard @@ -51842,7 +51842,7 @@ __metadata: eslint-plugin-unused-imports: "npm:^3.0.0" file-saver: "npm:^2.0.5" graphiql: "npm:^3.1.1" - graphql: "npm:^16.8.0" + graphql: "npm:16.8.1" graphql-sse: "npm:^2.5.4" input-otp: "npm:^1.4.2" js-cookie: "npm:^3.0.5" @@ -52022,7 +52022,7 @@ __metadata: glob: "npm:11.0.1" google-auth-library: "npm:8.9.0" googleapis: "npm:105.0.0" - graphql: "npm:16.8.0" + graphql: "npm:16.8.1" graphql-fields: "npm:2.0.3" graphql-middleware: "npm:^6.1.35" graphql-rate-limit: "npm:3.3.0"