redisvl is vulnerable to Query Injection
71
High Risk
redisvl interpolates Tag, Text, Num, and Geo filter values into RediSearch query strings. A filter value with metacharacters such as a quote, a bracket, or | can break out of its clause and change the query. Untrusted filter input can widen a query, skip an intersecting filter, or return records outside the intended scope, including across tenant boundaries under DIALECT 2. The fix escapes tag and text values, type-checks numeric and geo inputs, and parenthesizes each filter clause.
You are affected if you are using a version that falls within the vulnerable range and untrusted values reach a RedisVL query filter.
redisvl is vulnerable to Query Injection in versions 0.0.5 - 0.27.0.
Upgrade the redisvl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.