Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pgreadfile() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.