Vulnerability library
Security checkAugust 04, 2026

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A SQL injection vulnerability exists in the escapeValue() function used for parameter substitution. escapeValue() dispatches on the type of the parameter value, and two of its branches failed to escape safely. An attacker who can control a parameter value can terminate the enclosing string literal and have the rest of the value parsed as SQL.

Recommendation

Update the @hypequery/clickhouse package to the latest compatible version. Followings are version details:

  • Affected version(s): < 2.0.2
  • Patched version(s): 2.5.1

References

Could your website be exposed too?

SmartScanner can check your website for @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated August 04, 2026