GHSA-6wcc-39rp-hh9p
CRITICALCVE-2026-54658A SQL injection vulnerability exists in the escapeValue() function used for parameter substitution. escapeValue() dispatches on the type of the parameter value, and two of its branches failed to escape safely. An attacker who can control a parameter value can terminate the enclosing string literal and have the rest of the value parsed as SQL.
- Affected
- >=0, <2.5.1, < 2.0.2
- Fixed in
- 2.5.1
- Weakness
- CWE-89
- Published
- 2026-07-28
- Source
- osv