PT-2026-2123 · Parsl+1 · Parsl+1

Viralvaghela

·

Publicado

2026-01-06

·

Atualizado

2026-01-24

·

CVE-2026-21892

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Parsl versions prior to 2026.01.05
Description A SQL Injection issue exists in the parsl-visualize component. The application builds SQL queries using unsafe string formatting with user-supplied input (workflow id) taken directly from URL routes. This allows an unauthenticated attacker with access to the visualization dashboard to inject arbitrary SQL commands, potentially leading to data exfiltration or denial of service against the monitoring database.
Recommendations Update to version 2026.01.05 or later.

Exploit

Correção

DoS

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21892
GHSA-F2MF-Q878-GH58

Produtos afetados

Debian
Parsl