{"id":"GHSA-7x5c-vfhj-9628","summary":"Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw() ","details":"### Impact\n\nThis is a SQL Injection vulnerability in the MongoLite Aggregation Optimizer.\n\nAny Cockpit CMS instance running version **2.13.4 or earlier** with API access enabled\nis potentially affected.\n\n**Who is impacted:**\n- Any deployment where the `/api/content/aggregate/{model}` endpoint is publicly\n  accessible or reachable by untrusted users.\n- Attackers in possession of a **valid read-only API key** (the lowest privilege level)\n  can exploit this vulnerability — no admin access is required.\n\n**What an attacker can do:**\n- Inject arbitrary SQL via unsanitized field names in aggregation queries.\n- Bypass the `_state=1` published-content filter to access unpublished or restricted content.\n- Extract unauthorized data from the underlying SQLite content database.\n\n**Confidentiality impact is High.** Integrity and availability are not directly affected\nby this vulnerability.\n\n### Patches\n\nThis vulnerability has been **patched in version 2.13.5**.\n\nAll users running Cockpit CMS version **2.13.4 or earlier** are strongly advised to\nupgrade to **2.13.5 or later** immediately.\n\n- https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.13.5\n\nThe fix applies the same field-name sanitization introduced in v2.13.3 for `toJsonPath()`\nto the `toJsonExtractRaw()` method in `lib/MongoLite/Aggregation/Optimizer.php`,\nclosing the injection vector in the Aggregation Optimizer.","aliases":["CVE-2026-31891"],"modified":"2026-03-19T19:17:29.490977Z","published":"2026-03-17T17:07:41Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-17T17:07:41Z","nvd_published_at":"2026-03-18T04:17:19Z","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/Cockpit-HQ/Cockpit/security/advisories/GHSA-7x5c-vfhj-9628"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31891"},{"type":"PACKAGE","url":"https://github.com/Cockpit-HQ/Cockpit"},{"type":"WEB","url":"https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.13.5"}],"affected":[{"package":{"name":"cockpit-hq/cockpit","ecosystem":"Packagist","purl":"pkg:composer/cockpit-hq/cockpit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13.5"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.1.0","2.1.1","2.1.2","2.10.0","2.10.1","2.10.2","2.10.3","2.11.0","2.11.1","2.11.2","2.11.3","2.11.4","2.12.0","2.12.1","2.13.0","2.13.1","2.13.2","2.13.3","2.13.4","2.2.0","2.2.1","2.2.2","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9","2.4.0","2.4.1","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.6.2","2.6.3","2.7.0","2.7.1","2.7.2","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.9.0","2.9.1","2.9.2","2.9.3","2.9.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7x5c-vfhj-9628/GHSA-7x5c-vfhj-9628.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}