Cache variables with the operations when transforms exist on the root level even if variables change in the further requ
- Severity:
- Medium
Description
When you have transforms on the root level or single source with transforms, and the client sends the same query with different variables, the initial variables are used in all following requests until the cache evicts DocumentNode.
Recommendation
Update the @graphql-mesh/runtime package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.96.5, < 0.96.9
- Patched version(s): 0.96.9
References
Related Issues
- JS Html Sanitizer allows XSS when used with contentEditable - CVE-2025-29771
- SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering - CVE-2025-67647
- matrix-js-sdk has insufficient validation when considering a room to be upgraded by another - CVE-2025-59160
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - vega - CVE-2025-26619
You might also like:
- Tags:
- npm
- @graphql-mesh/runtime
Anything's wrong? Let us know Last updated on February 28, 2025


