inspector-apm/neuron-ai is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
70
High Risk
Affected versions of this package are vulnerable to SQL Injection due to improper neutralization of prompt elements in the database query tool. The old code directly concatenated user-supplied input into SQL queries without using parameterized statements when handling the prompt, allowing attackers to execute arbitrary SQL commands on the underlying database. The patched code enforces the use of named placeholders and parameter binding, effectively neutralizing this threat by separating SQL code from data.
You are affected if you are using a version that falls within the vulnerable range.
inspector-apm/neuron-ai is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 1.11.4 - 2.2.9.
Upgrade the inspector-apm/neuron-ai library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant