CVE-2026-54658

Source
https://cve.org/CVERecord?id=CVE-2026-54658
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54658.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54658
Aliases
Published
2026-07-28T22:18:48Z
Modified
2026-08-12T03:51:19Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
Details

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject arbitrary SQL. This issue is fixed in version 2.0.2. Version 2.0.2 fixes string parameters, while version 2.5.1 fixes all known vectors. Upgrading to 2.5.1 or later is the only complete fix. In versions 2.0.2 through 2.5.0, serializing non-scalar parameters with  JSON.stringify()  before passing them is a workaround for the object/array vector only.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54658.json"
}
References

Affected packages

Git / github.com/hypequery/hypequery

Affected ranges

Type
GIT
Repo
https://github.com/hypequery/hypequery
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0.2"
        },
        {
            "fixed": "2.5.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54658.json"