This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login. Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: A critical flaw in the RBI Assistant Platform allows attackers to steal admin tokens via a GraphQL mutation.โฆ
๐ข **Vendor**: Restaurant Brands International (RBI). ๐ **Products**: Assistant Platform (used by Burger King, Popeyes, Tim Hortons). ๐ **Affected Versions**: All versions released **before 2025-09-06**.โฆ
๐ **Privileges**: Escalates from standard user to **Full Administrator**. ๐ **Data Access**: Complete access to the entire platform backend. ๐ **Real World**: Attackers can control drive-thru systems and customer data.โฆ
๐ **Check**: Scan for the `createToken` GraphQL endpoint. ๐งช **Test**: Attempt to trigger the mutation with low-privilege credentials. ๐ก **Indicator**: Look for unexpected admin token generation in logs.โฆ
๐ ๏ธ **Fix**: Update to version **2025-09-06 or later**. โ **Official Patch**: RBI has acknowledged the issue and released a fix. ๐ฅ **Action**: Immediate upgrade required for all Assistant Platform instances.โฆ