Skip to content
← archivevulnerability · 23 Sep 2026 · 21:51 UTC

GHSA-wmw4-mw6x-6vfm: ReactPress has SQL injection via dynamic column names in TypeORM query builders

VULNCVE-2026-61685source · GTH
HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

## Summary ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter *names* as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing unauthenticated attackers to inject SQL through crafted query string keys. ## Impact An unauthenticated remote attacker can perform blind SQL injection against the application database, potentially exfiltrating sensitive data (users, settings, API keys, article content, etc.). …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected