PT-2026-2123 · Parsl+1 · Parsl+1
Viralvaghela
·
Published
2026-01-06
·
Updated
2026-01-24
·
CVE-2026-21892
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Parsl versions prior to 2026.01.05
Description
A SQL Injection issue exists in the parsl-visualize component. The application builds SQL queries using unsafe string formatting with user-supplied input (
workflow id) taken directly from URL routes. This allows an unauthenticated attacker with access to the visualization dashboard to inject arbitrary SQL commands, potentially leading to data exfiltration or denial of service against the monitoring database.Recommendations
Update to version 2026.01.05 or later.
Exploit
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Parsl