cycle/database is vulnerable to SQL Injection
81
High Risk
Cycle Database's PostgreSQL JSON expression builder inserts non-numeric JSON path segments directly between single quote characters when compiling whereJson(), whereJsonContains(), whereJsonContainsKey(), and related query methods. A path segment containing an apostrophe closes the SQL string literal early, so the path can add extra predicates or operators to the compiled WHERE clause. A crafted path can bypass a separately applied tenant or authorization condition and change which rows a SELECT, UPDATE, or DELETE affects, even though the comparison value stays parameterized. The fix doubles embedded apostrophes with str_replace() before writing them into the JSON path fragment, so a crafted segment can no longer escape the literal.
You are affected if you are using a version that falls within the vulnerable range and you use the PostgreSQL driver's JSON query methods (whereJson(), whereJsonContains(), whereJsonContainsKey(), or similar) with a JSON path segment that is influenced by user input.
cycle/database is vulnerable to SQL Injection in versions 2.6.0 - 2.23.2.
Upgrade the cycle/database library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.