GHSA-wc3v-3457-c8cm
MODERATECVE-2026-8462An authenticated tenant can inject arbitrary SQL through the valueProperty or groupBy fields of POST /api/v1/meters. The injection passes the application's JSONPath validation check and executes against the shared ClickHouse database, which contains event data for all tenants with no row-level security. Any authenticated tenant can read or write every other tenant's metering data.
- Affected
- < 1.0.0-beta.228, >=0, <1.0.0-beta.228
- Fixed in
- 1.0.0-beta.228
- Weakness
- CWE-89
- Published
- 2026-06-04
- Source
- github