Intel

AIKIDO-2026-241038

cycle/database is vulnerable to SQL Injection

SQL InjectionGHSA-h9gf-7rq8-q8h8 Published 2 days ago

81

High Risk

This Affects:

PHPcycle/database
2.6.0 - 2.23.2
Fixed in 2.23.3
Are you affected? Scan for Free

TL;DR

Cycle Database's PostgreSQL JSON expression builder inserts non-numeric JSON path segments directly between single quote characters when compiling whereJson(), whereJsonContains(), whereJsonContainsKey(), and related query methods. A path segment containing an apostrophe closes the SQL string literal early, so the path can add extra predicates or operators to the compiled WHERE clause. A crafted path can bypass a separately applied tenant or authorization condition and change which rows a SELECT, UPDATE, or DELETE affects, even though the comparison value stays parameterized. The fix doubles embedded apostrophes with str_replace() before writing them into the JSON path fragment, so a crafted segment can no longer escape the literal.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the PostgreSQL driver's JSON query methods (whereJson(), whereJsonContains(), whereJsonContainsKey(), or similar) with a JSON path segment that is influenced by user input.

Background info

cycle/database is vulnerable to SQL Injection in versions 2.6.0 - 2.23.2.

How to fix this

Upgrade the cycle/database library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform