Skip to content

fix: eb.ref(col, '->$').key(key) is injectable.#1727

Merged
igalklebanov merged 1 commit intokysely-org:masterfrom
igalklebanov:fix-$-key-injection-vulnerability
Mar 4, 2026
Merged

fix: eb.ref(col, '->$').key(key) is injectable.#1727
igalklebanov merged 1 commit intokysely-org:masterfrom
igalklebanov:fix-$-key-injection-vulnerability

Conversation

@igalklebanov
Copy link
Copy Markdown
Member

@igalklebanov igalklebanov commented Mar 4, 2026

Hey 👋

eb.ref(col, '->$').key(injection) is a thing. This PR denies it.

@vercel
Copy link
Copy Markdown

vercel Bot commented Mar 4, 2026

@igalklebanov is attempting to deploy a commit to the Kysely Team Team on Vercel.

A member of the Team first needs to authorize it.

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new Bot commented Mar 4, 2026

commit: 5f9e409

@igalklebanov igalklebanov marked this pull request as ready for review March 4, 2026 00:34
@igalklebanov igalklebanov added bug Something isn't working mysql Related to MySQL sqlite Related to sqlite security internal labels Mar 4, 2026
@igalklebanov igalklebanov merged commit 0a602bf into kysely-org:master Mar 4, 2026
29 of 31 checks passed
@igalklebanov igalklebanov deleted the fix-$-key-injection-vulnerability branch March 4, 2026 00:40
Br1an67 pushed a commit to Br1an67/kysely that referenced this pull request Mar 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working internal mysql Related to MySQL security sqlite Related to sqlite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant