{"id":"GHSA-r8cr-4f9w-7r75","summary":"Netmaker has a boolean‑based SQL Injection","details":"# SQL Injection in Netmaker SQLite Database Backend\n\n## Summary\n\nThe `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform **boolean-based SQL injection**.\n\n---\n\n## Details\n\nThe endpoint:\n\n\nDELETE /api/dns/{network}/{domain}\n\n\npasses user-controlled path parameters through the following flow:\n\n\nlogic.DeleteDNS → database.DeleteRecord → sqliteDeleteRecord\n\n\nDepending on the configured database backend, the request eventually reaches the SQLite database implementation.\n\n### Vulnerable Code\n\nThe SQL query is constructed using direct string concatenation without parameterization.\n\n```go\n// database/sqlite.go\ndeleteSQL := \"DELETE FROM \" + tableName + \" WHERE key = \\\"\" + key + \"\\\"\"\n\nThe key value originates from user input ({domain} path parameter) and is embedded directly into the SQL query.\n\nExploitation\n\nAn authenticated attacker can inject SQL operators into the {domain} path parameter to manipulate the query logic.\n\nBecause this injection is boolean-based, attackers extract data indirectly by observing the outcome of the operation:\n\nIf the injected condition evaluates true, the DNS record is deleted.\n\nIf the condition evaluates false, the DNS record remains.\n\nBy repeating this process, an attacker can infer information such as:\n\nDatabase table names\n\nColumn names\n\nColumn values\n\nValue lengths\n\nImpact\n\nAn authenticated attacker can exploit this vulnerability to extract data from arbitrary database tables when using the SQLite backend.\n\nUnaffected backend:\n\nPostgreSQL (uses parameterised queries with $1, $2 placeholders)\n\nPatches\n\nThis vulnerability is fixed in version (fill in).\n\nThe patch replaces string concatenation with parameterised SQL queries for all user-supplied values in database operations.\n\n\n---\nCredit\n\nArtem Danilov\n(Positive Technologies)\n\nDaniil Satyaev (Independent)","aliases":["CVE-2026-32599","GO-2026-6485"],"modified":"2026-09-28T17:11:03.727458664Z","published":"2026-09-15T19:48:49Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-15T19:48:49Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/gravitl/netmaker/security/advisories/GHSA-r8cr-4f9w-7r75"},{"type":"PACKAGE","url":"https://github.com/gravitl/netmaker"},{"type":"WEB","url":"https://github.com/gravitl/netmaker/releases/tag/v1.5.0"}],"affected":[{"package":{"name":"github.com/gravitl/netmaker","ecosystem":"Go","purl":"pkg:golang/github.com/gravitl/netmaker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-r8cr-4f9w-7r75/GHSA-r8cr-4f9w-7r75.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}