Skip to content

[LI-197038] Prevent GraphQL injection in transfer method configuration queries - #155

Closed
brsouzapaypal wants to merge 1 commit into
hyperwallet:masterfrom
brsouzapaypal:bugfix/LI-197038-graphql-injection
Closed

brsouzapaypal wants to merge 1 commit into
hyperwallet:masterfrom
brsouzapaypal:bugfix/LI-197038-graphql-injection

Conversation

@brsouzapaypal

@brsouzapaypal brsouzapaypal commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary

Fixes a GraphQL injection vulnerability (CWE-943, LI-197038) in the transfer method configuration queries. Caller-supplied values were interpolated directly into the GraphQL query string via String(format:), so a crafted value could terminate its field and append arbitrary GraphQL (e.g. an introspection selection).

Changes

  • GraphQlQuery: new protocol-extension helpers
    • sanitizeGraphQlLiteral(_:): allowlist of GraphQL-name characters for values interpolated as unquoted enum/scalar literals.
    • escapeGraphQlString(_:): escapes \ and " for values embedded inside quoted strings.
  • Wired the helpers into every query that interpolates caller input:
    • HyperwalletTransferMethodConfigurationFieldQuery (userToken, profile, country, currency, transferMethodType)
    • HyperwalletTransferMethodConfigurationKeysQuery (userToken)
    • HyperwalletTransferMethodTypesFeesAndProcessingTimesQuery (userToken, country, currency)
    • HyperwalletTransferMethodUpdateConfigurationFieldQuery (transferMethodToken)

Scope note

The ticket enumerates the field query fields. The fix was intentionally broadened to every query that interpolates caller input (KeysQuery, FeesAndProcessingTimes, and all userToken values), since the same unsafe pattern repeats there.

Testing

  • Added unit tests in HyperwalletTransferMethodConfigurationFieldQueryTests covering injection neutralization in unquoted literals, quote escaping in quoted strings, and preservation of valid values for all four queries.
  • Validated the output of all four queries locally; legitimate values are unchanged and injection payloads are neutralized.

CI note

The iOS Core SDK CI workflow fails at the Carthage [Install dependencies] step while building the Hippolyte test dependency under Xcode 16.2 (Build Failed, exit code 70), before the project is compiled or the test/lint steps run. This is a pre-existing pipeline failure unrelated to this change.

How this was verified:

  1. Enabled GitHub Actions on the fork (disabled by default on forks) and dispatched the iOS Core SDK CI workflow against this branch.
  2. Cross-checked the upstream master CI run, which fails at the same early stage, confirming the failure predates this change.

Because the dependency build fails before the test phase, the test and lint steps cannot execute in CI until the Hippolyte build is repaired. The added XCTest cases will run once the pipeline is healthy. In the meantime the change was validated locally.

…n queries

Caller-supplied values were interpolated directly into GraphQL query strings via String(format:), allowing a crafted value to break out of its field and append arbitrary GraphQL (CWE-943).

Add two helpers on the GraphQlQuery protocol and wire them into every query that interpolates caller input:
- sanitizeGraphQlLiteral: allowlist of GraphQL-name characters for unquoted enum/scalar literals (country, currency, profile, transferMethodType)
- escapeGraphQlString: escape backslashes and double quotes for values embedded inside quoted strings (user and transfer method tokens)

Legitimate values pass through unchanged; injection payloads lose the syntax characters they rely on. Adds unit tests covering injection neutralization, quote escaping, and preservation of valid values.
@brsouzapaypal

Copy link
Copy Markdown
Author

Closing this PR — no longer needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant