{"id":"CVE-2026-5423","aliases":["GHSA-fcpg-3fw5-vc65"],"url":"https://o3.security/vulnerability/CVE-2026-5423","summary":"Subscription Authentication Bypass via Unverified connectionParams.jwt","details":"@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for the purposes of @authentication and @subscriptionsAuthorization directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users.\nUpgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix.","published":"2026-08-06T15:15:29.124Z","modified":"2026-08-20T03:30:43.914139242Z","cvss":null,"epss":{"score":0.00357,"percentile":0.29114,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://registry.npmjs.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5423.json"},{"type":"ADVISORY","url":"https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65"},{"type":"ADVISORY","url":"https://neo4j.com/security/CVE-2026-5423"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5423"},{"type":"PACKAGE","url":"https://github.com/neo4j/graphql"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T03:30:43.914139242Z"}}