datacontract-cli is vulnerable to SQL Injection
68
Medium Risk
A data contract can define a quality.type: sql rule whose query is executed against the configured data source when the contract is tested. Before the fix, that query is run as written, so a contract from an untrusted source can execute write statements and DuckDB COPY or ATTACH operations instead of a read-only check. This lets the contract modify data and read or write local files through the database engine rather than only validating data quality. The fix requires such rules to be read-only and reports DDL, DML, COPY, and ATTACH statements as a failed check for every data source.
You are affected if you are using a version that falls within the vulnerable range and you run datacontract test on a data contract from an untrusted source that defines a quality.type: sql rule against a configured data source.
datacontract-cli is vulnerable to SQL Injection in versions 0.10.14 - 1.1.1.
Upgrade the datacontract-cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.