Loading market data...
← Back to CVE feed

CVE-2026-54658

CRITICAL CVSS 9.8 View on NVD ↗

Description

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject arbitrary SQL. This issue is fixed in version 2.0.2.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Jul 28, 2026 23:17 UTC Modified: Jul 29, 2026 13:18 UTC