PT-2026-34606 · Daptin+1 · Daptin+1
Vashuvats
·
Published
2026-04-22
·
Updated
2026-05-07
·
CVE-2026-41422
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Daptin versions prior to 0.11.4
Description
The '/aggregate/:typename' endpoint accepts
column and group query parameters that are passed without validation to goqu.L(), a raw SQL literal expression builder. This bypasses parameterization, allowing authenticated users with any valid session to inject arbitrary SQL expressions. This can lead to the extraction of data from any table via subqueries, disclosure of database internals, and exfiltration of cross-table data via correlated subqueries.Recommendations
Update to version 0.11.4.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Daptin
Github.Com/Daptin/Daptin