{"id":"GHSA-rw2c-8rfq-gwfv","summary":"Daptin: SQL injection via unvalidated goqu.L() calls in aggregate API","details":"## Summary\n\nThe `/aggregate/:typename` endpoint accepted `column` and `group` query parameters that were passed verbatim to `goqu.L()` — a raw SQL literal expression builder — without any validation. This bypassed all parameterization and allowed authenticated users with any valid session to inject arbitrary SQL expressions.\n\n## Impact\n\nAn authenticated low-privilege user could:\n- Extract data from any table via subquery: `(SELECT group_concat(email) FROM user_account) as leak`\n- Disclose database internals: `sqlite_version()`, `(SELECT sql FROM sqlite_master)`\n- Exfiltrate cross-table data via correlated subqueries\n\nThe vulnerability was confirmed locally; `user_account.email` values were extracted via a crafted `column` parameter by a non-admin user.\n\n## Root Cause\n\n`goqu.L(userInput)` in `server/resource/resource_aggregate.go` inserted user-supplied query parameters directly into the SQL string with no validation.\n\n## Fix (v0.11.4)\n\nAll `goqu.L()` calls on user-controlled input were eliminated and replaced with:\n- Structural expression parsing supporting all documented API forms\n- Schema-based column validation (column names checked against entity schema via `TableInfo().GetColumnByName()`)\n- Exact-match allowlist for aggregate functions (`count`, `sum`, `avg`, `min`, `max`, `first`, `last`) and scalar functions (`date`, `strftime`, `upper`, `lower`, etc.)\n- Safe goqu constructors (`goqu.I()`, `goqu.SUM()`, `goqu.Func()`) for all generated expressions\n- `allowedTables` scope enforcement: qualified column refs (`table.col`) validated against root entity + explicitly joined tables only\n\nTwo additional DoS bugs were fixed in the same commit: `uuid.MustParse` panic on malformed UUID input and an index-out-of-range panic in `ToOrderedExpressionArray` on empty sort expressions.\n\n## Credits\n\nReported by @VashuVats.","aliases":["CVE-2026-41422","GO-2026-5640"],"modified":"2026-06-25T23:11:35.232472023Z","published":"2026-04-22T17:38:02Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-22T17:38:02Z","nvd_published_at":"2026-05-07T15:16:06Z","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/daptin/daptin/security/advisories/GHSA-rw2c-8rfq-gwfv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41422"},{"type":"PACKAGE","url":"https://github.com/daptin/daptin"},{"type":"WEB","url":"https://github.com/daptin/daptin/releases/tag/v0.11.4"}],"affected":[{"package":{"name":"github.com/daptin/daptin","ecosystem":"Go","purl":"pkg:golang/github.com/daptin/daptin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.11.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rw2c-8rfq-gwfv/GHSA-rw2c-8rfq-gwfv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"}]}