{"id":"GHSA-9pp3-53p2-ww9v","summary":"@vendure/core has a SQL Injection vulnerability","details":"## Summary\n\nAn unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database. This affects all supported database backends (PostgreSQL, MySQL/MariaDB, SQLite).\n\nThe Admin API is also affected, though exploitation there requires authentication.\n\n## Affected versions\n\n- `@vendure/core` \u003c 2.3.4\n- `@vendure/core` \u003e= 3.0.0, \u003c 3.5.7\n- `@vendure/core` \u003e= 3.6.0, \u003c 3.6.2\n\nNote: versions 2.3.4 and above in the 2.x line are patched. There were no 2.4.x or 2.x releases between 2.3.x and 3.0.0.\n\n## Patched versions\n\n- `@vendure/core` 2.3.4\n- `@vendure/core` 3.5.7\n- `@vendure/core` 3.6.2\n\n## Details\n\nIn `ProductService.findOneBySlug`, the request context's `languageCode` value is interpolated into a SQL `CASE` expression via a JavaScript template literal:\n\n```ts\n.addSelect(\n    `CASE translation.languageCode WHEN '${ctx.languageCode}' THEN 2 WHEN '${ctx.channel.defaultLanguageCode}' THEN 1 ELSE 0 END`,\n    'sort_order',\n)\n```\n\nTypeORM has no opportunity to parameterize this value because it is embedded directly into the SQL string before being passed to the query builder.\n\nThe `languageCode` value can originate from the HTTP query string and is set on the request context for every incoming API request. The value is cast to the `LanguageCode` TypeScript type at compile time, but no runtime validation is performed -- the raw query string value is used as-is.\n\n## Attack vector\n\nAn unauthenticated attacker can append a crafted `languageCode` query parameter to any Shop API request to inject arbitrary SQL into the query. No user interaction is required. The vulnerable endpoint is exposed on every default Vendure installation.\n\n## Mitigation\n\n**Upgrade to a patched version immediately.**\n\nIf you cannot upgrade right away, apply the following hotfix to `RequestContextService.getLanguageCode` to validate the `languageCode` input at the boundary. This blocks injection payloads before they can reach any query:\n\n```ts\nprivate getLanguageCode(req: Request, channel: Channel): LanguageCode | undefined {\n    const queryLanguageCode = req.query?.languageCode as string | undefined;\n    const isValidFormat = queryLanguageCode && /^[a-zA-Z0-9_-]+$/.test(queryLanguageCode);\n    return (\n        (isValidFormat ? (queryLanguageCode as LanguageCode) : undefined) ??\n        channel.defaultLanguageCode ??\n        this.configService.defaultLanguageCode\n    );\n}\n```\n\nThis replaces the existing `getLanguageCode` method in `packages/core/src/service/helpers/request-context/request-context.service.ts`. Invalid values are silently dropped and the channel's default language is used instead.\n\nThe patched versions additionally convert the vulnerable SQL interpolation to a parameterized query as defense in depth.","aliases":["CVE-2026-40887"],"modified":"2026-05-05T16:05:31.510360Z","published":"2026-04-14T22:38:01Z","database_specific":{"nvd_published_at":"2026-04-21T20:17:02Z","cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-04-14T22:38:01Z"},"references":[{"type":"WEB","url":"https://github.com/vendurehq/vendure/security/advisories/GHSA-9pp3-53p2-ww9v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40887"},{"type":"PACKAGE","url":"https://github.com/vendurehq/vendure"}],"affected":[{"package":{"name":"@vendure/core","ecosystem":"npm","purl":"pkg:npm/%40vendure/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-9pp3-53p2-ww9v/GHSA-9pp3-53p2-ww9v.json"}},{"package":{"name":"@vendure/core","ecosystem":"npm","purl":"pkg:npm/%40vendure/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.6.0"},{"fixed":"3.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-9pp3-53p2-ww9v/GHSA-9pp3-53p2-ww9v.json"}},{"package":{"name":"@vendure/core","ecosystem":"npm","purl":"pkg:npm/%40vendure/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.7.4"},{"fixed":"2.3.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-9pp3-53p2-ww9v/GHSA-9pp3-53p2-ww9v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}