PT-2026-2123 · Parsl+1 · Parsl+1

Viralvaghela

·

Published

2026-01-06

·

Updated

2026-01-24

·

CVE-2026-21892

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Parsl versions prior to 2026.01.05
Description A SQL Injection issue exists in the parsl-visualize component. The application builds SQL queries using unsafe string formatting with user-supplied input (workflow id) taken directly from URL routes. This allows an unauthenticated attacker with access to the visualization dashboard to inject arbitrary SQL commands, potentially leading to data exfiltration or denial of service against the monitoring database.
Recommendations Update to version 2026.01.05 or later.

Exploit

Fix

DoS

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-21892
GHSA-F2MF-Q878-GH58

Affected Products

Debian
Parsl