Description
A SQL injection vulnerability exists in the escapeValue() function used for parameter substitution. escapeValue() dispatches on the type of the parameter value, and two of its branches failed to escape safely. An attacker who can control a parameter value can terminate the enclosing string literal and have the rest of the value parsed as SQL.
Recommendation
Update the @hypequery/clickhouse package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.2
- Patched version(s): 2.5.1
References
Could your website be exposed too?
SmartScanner can check your website for @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution - CVE-2026-24737
- Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that - CVE-2026-33468
- CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS - CVE-2026-26028
- Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click - CVE-2026-43941


