PT-2026-34606 · Daptin+1 · Daptin+1

Vashuvats

·

Published

2026-04-22

·

Updated

2026-05-07

·

CVE-2026-41422

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Daptin versions prior to 0.11.4
Description The '/aggregate/:typename' endpoint accepts column and group query parameters that are passed without validation to goqu.L(), a raw SQL literal expression builder. This bypasses parameterization, allowing authenticated users with any valid session to inject arbitrary SQL expressions. This can lead to the extraction of data from any table via subqueries, disclosure of database internals, and exfiltration of cross-table data via correlated subqueries.
Recommendations Update to version 0.11.4.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-41422
GHSA-RW2C-8RFQ-GWFV

Affected Products

Daptin
Github.Com/Daptin/Daptin