Feed/CVE-2026-54658
CVE-2026-54658CRITICALCVSS 9.8

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

Published Jul 28, 2026·Updated Aug 4, 2026

NVD Description

### Impact A SQL injection vulnerability exists in the `escapeValue()` function used for parameter substitution. Attackers who can control parameter values can inject arbitrary SQL by using a trailing backslash to escape the closing quote. Who is impacted: All users of @hypequery/clickhouse versions prior to 2.0.2 who pass user-controlled input as query parameters. ### Patches The vulnerability has been patched in version 2.0.2. The fix properly escapes backslashes before escaping single quotes ### Workarounds No workaround exists other than upgrading. Manual input validation/sanitization is not recommended as a mitigation - the library must handle escaping correctly.

Affected Packages (1)

@hypequery/clickhouseNPM
Fixed in 2.0.2

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free