{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@hypequery/clickhouse--2.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@hypequery/clickhouse (\u003c 2.0.2)"],"_cs_severities":["critical"],"_cs_tags":["sql-injection","vulnerability","npm","clickhouse","supply-chain"],"_cs_type":"advisory","_cs_vendors":["hypequery"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability, identified as CVE-2026-54658, has been discovered in the \u003ccode\u003e@hypequery/clickhouse\u003c/code\u003e npm package, specifically within its \u003ccode\u003eescapeValue()\u003c/code\u003e function. This flaw affects all versions of the library prior to 2.0.2. Attackers can exploit this by providing user-controlled input containing a trailing backslash character (\u003ccode\u003e\\\u003c/code\u003e) followed by arbitrary SQL code when interacting with an application that uses the vulnerable library to query a ClickHouse database. The \u003ccode\u003eescapeValue()\u003c/code\u003e function's improper handling of backslashes before escaping single quotes allows the attacker's malicious SQL to be injected and executed. This can lead to unauthorized data access, modification, or deletion, posing a significant threat to data integrity and confidentiality for organizations using this package. The vulnerability highlights a supply chain risk for applications relying on third-party libraries for database interactions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a web application or service that utilizes the \u003ccode\u003e@hypequery/clickhouse\u003c/code\u003e library to interact with a ClickHouse database.\u003c/li\u003e\n\u003cli\u003eThe attacker discovers an input field or parameter in the application that processes user-supplied values, which are subsequently passed into a SQL query via the vulnerable \u003ccode\u003eescapeValue()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious input string that contains legitimate data followed by a backslash (\u003ccode\u003e\\\u003c/code\u003e) and then their arbitrary SQL injection payload (e.g., \u003ccode\u003euser_input_data\\' OR 1=1--\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eWhen the application uses \u003ccode\u003e@hypequery/clickhouse\u003c/code\u003e to prepare the query, the \u003ccode\u003eescapeValue()\u003c/code\u003e function is called on the malicious input.\u003c/li\u003e\n\u003cli\u003eDue to the flaw in versions prior to 2.0.2, the trailing backslash in the attacker's input escapes the legitimate single quote character that the library would normally add to close the string.\u003c/li\u003e\n\u003cli\u003eThis mis-escaping causes the attacker's SQL injection payload (e.g., \u003ccode\u003eOR 1=1--\u003c/code\u003e) to be interpreted as part of the SQL query itself, rather than as literal string data.\u003c/li\u003e\n\u003cli\u003eThe application then executes the manipulated SQL query against the backend ClickHouse database.\u003c/li\u003e\n\u003cli\u003eThe arbitrary SQL code is executed on the ClickHouse database, allowing the attacker to perform actions such as data exfiltration, unauthorized data modification, or other database manipulation, depending on the attacker's payload and the database user's privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-54658 allows attackers to achieve arbitrary SQL execution within the context of the affected ClickHouse database. This can lead to severe consequences, including full compromise of the database's data, such as exfiltration of sensitive information, modification of existing records, or deletion of critical data. Organizations whose applications rely on \u003ccode\u003e@hypequery/clickhouse\u003c/code\u003e are at risk of significant data breaches and operational disruption if their user-facing inputs are not adequately protected. No specific victim counts or sectors were identified in the advisory, but any application using the vulnerable library is exposed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@hypequery/clickhouse\u003c/code\u003e to version 2.0.2 or later immediately to apply the patch for CVE-2026-54658.\u003c/li\u003e\n\u003cli\u003eReview applications using \u003ccode\u003e@hypequery/clickhouse\u003c/code\u003e for proper input validation on all user-controlled parameters that are passed into database queries.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T22:21:07Z","date_published":"2026-07-28T22:21:07Z","id":"https://feed.craftedsignal.io/briefs/2026-07-clickhouse-sql-injection/","summary":"A SQL injection vulnerability exists in the `escapeValue()` function of the `@hypequery/clickhouse` library, affecting versions prior to 2.0.2, allowing attackers to leverage a trailing backslash in user-controlled query parameters to bypass escaping mechanisms, leading to arbitrary SQL execution against ClickHouse databases.","title":"SQL Injection Vulnerability in @hypequery/clickhouse Allows Arbitrary SQL Execution","url":"https://feed.craftedsignal.io/briefs/2026-07-clickhouse-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - @Hypequery/Clickhouse (\u003c 2.0.2)","version":"https://jsonfeed.org/version/1.1"}