GHSA-xp6r-8pcc-xv5p

Suggest an improvement
Source
https://github.com/advisories/GHSA-xp6r-8pcc-xv5p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-xp6r-8pcc-xv5p/GHSA-xp6r-8pcc-xv5p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xp6r-8pcc-xv5p
Aliases
  • CVE-2026-31069
Published
2026-05-19T18:32:11Z
Modified
2026-09-10T03:51:07Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
BillaBear is Vulnerable to SQL Injection in the EventRepository
Details

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands.

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-04T21:38:38Z",
    "nvd_published_at":  "2026-05-19T16:16:20Z",
    "severity":  "HIGH"
}
References

Affected packages

Packagist / billabear/billabear

Package

Name
billabear/billabear
Purl
pkg:composer/billabear/billabear

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2025.01.03

Affected versions

v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.1.1
v1.1.2
v1.1.3
2023.*
2023.04.01
2023.04.02
2023.04.03
2024.*
2024.01.01
2024.01.02
2024.01.03
2025.*
2025.01.01
2025.01.02
2025.01.03

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-xp6r-8pcc-xv5p/GHSA-xp6r-8pcc-xv5p.json"