go package report

Is github.com/openmeterio/openmeter safe?

1 known vulnerability, worst severity MODERATE.

cvss
8.9

how bad it is if exploited, out of 10

epss
0.60%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-wc3v-3457-c8cm, the advisory selected below

// advisories

GHSA-wc3v-3457-c8cm

MODERATECVE-2026-8462

An authenticated tenant can inject arbitrary SQL through the valueProperty or groupBy fields of POST /api/v1/meters. The injection passes the application's JSONPath validation check and executes against the shared ClickHouse database, which contains event data for all tenants with no row-level security. Any authenticated tenant can read or write every other tenant's metering data.

Affected
< 1.0.0-beta.228, >=0, <1.0.0-beta.228
Fixed in
1.0.0-beta.228
Weakness
CWE-89
Published
2026-06-04
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 01:36 UTC. The most recent advisory here was published 2026-06-04. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/openmeterio/openmeter safe? go package security report | CyberXYZ