Tag
critical
advisory
SQL Injection Vulnerability in @hypequery/clickhouse Allows Arbitrary SQL Execution
2 TTPsA SQL injection vulnerability exists in the `escapeValue()` function of the `@hypequery/clickhouse` library, affecting versions prior to 2.0.2, allowing attackers to leverage a trailing backslash in user-controlled query parameters to bypass escaping mechanisms, leading to arbitrary SQL execution against ClickHouse databases.
@hypequery/clickhouse
sql-injection
vulnerability
npm
clickhouse
supply-chain
2t
high
advisory
Dify MyScale Backend SQL Injection Vulnerability (CVE-2026-61461)
1 rule 4 TTPs 1 CVEA high-severity SQL injection vulnerability, CVE-2026-61461, exists in the MyScale vector store backend of Dify versions prior to 1.16.0-rc1, allowing attackers with low privileges to execute arbitrary SQL commands via unsanitized search parameters, leading to unauthorized data manipulation in the underlying ClickHouse database.
Dify
sql-injection
web-vulnerability
clickhouse
1r
4t
1c