Improper Neutralization of Special Elements in Ash-Project Ash_SQL
CVE-2026-78691
What is CVE-2026-78691?
The Ash_Project ash_sql library exhibits a vulnerability due to improper handling of special characters in user-supplied search terms. Attackers may exploit this flaw by injecting SQL LIKE wildcards, leading to unintended query behavior. The escape mechanisms in place are insufficient, as they fail to effectively neutralize backslashes already present in the input. This allows malicious users to manipulate search patterns, potentially widening matches, evading security checks, or causing query failures with malformed inputs. This vulnerability affects specific versions of ash_sql prior to 0.7.1, emphasizing the need for users to promptly update to secure their applications.
Affected Version(s)
ash_sql 0.1.1-rc.10 < 0.7.1
ash_sql cfc7da474c5be2190fd62664a83a689377a8d512
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
