CVE-2026-30241 | mercurius-js mercurius up to 16.7.x GraphQL Subscription authorization (GHSA-m4h2-mjfm-mp55)
A vulnerability labeled as critical has been found in mercurius-js mercurius up to 16.7.x. Affected is an unknown function of the component GraphQL Subscription Handler. The manipulation results in incorrect authorization.
This vulnerability is known as CVE-2026-30241. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.