Descrição
Improper Neutralization of Special Elements used in an SQL Command (-SQL Injection-) vulnerability in elixir-ecto postgrex (-Elixir.Postgrex.Notifications- module) allows SQL Injection. The channel argument passed to -Elixir.Postgrex.Notifications-:listen/3 and -Elixir.Postgrex.Notifications-:unlisten/3 is interpolated directly into LISTEN -...- / UNLISTEN -...- SQL statements without escaping the - character. An attacker who can influence the channel name can inject a - to break out of the quoted identifier and append arbitrary SQL. Because the notifications connection uses the PostgreSQL simple query protocol, multi-statement payloads are accepted, allowing DDL and DML commands to be chained (e.g. ; DROP TABLE ...; --). The same unsanitized interpolation also occurs in handle_connect/1 when replaying LISTEN commands after a reconnect. This vulnerability is associated with program file lib/postgrex/notifications.ex and program routines -Elixir.Postgrex.Notifications-:listen/3, -Elixir.Postgrex.Notifications-:unlisten/3, -Elixir.Postgrex.Notifications-:handle_connect/1. This issue affects postgrex: from 0.16.0 before 0.22.2.
- Publicação
- 2026-05-12 15:16:12
- Versões afetadas
- unknown
- Tipo
- Package
- Última alteração
- 2026-07-24 15:17:16
- Vetor
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H