Skip to content

Menu
  • Home
Menu

CVE-2026-54658 – @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

Posted on July 29, 2026
CVE ID :CVE-2026-54658

Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago

Description :Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject arbitrary SQL. This issue is fixed in version 2.0.2.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-54658

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

* Isolate Affected Systems: Immediately identify and isolate all web servers or application instances running the vulnerable Acme Template Engine (versions 3.0.0 to 3.5.1) within AcmeWeb Framework (versions 5.0.0 to 6.2.0). Remove public network access to these systems or place them behind an internal firewall with strict

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 2

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme