{"id":"GHSA-wmw4-mw6x-6vfm","summary":"ReactPress has SQL injection via dynamic column names in TypeORM query builders","details":"## Summary\n\nReactPress API list endpoints build TypeORM `QueryBuilder` conditions using\nunsanitized HTTP query parameter *names* as SQL column identifiers\n(e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column\nnames, allowing unauthenticated attackers to inject SQL through crafted\nquery string keys.\n\n## Impact\n\nAn unauthenticated remote attacker can perform blind SQL injection against\nthe application database, potentially exfiltrating sensitive data (users,\nsettings, API keys, article content, etc.).\n\n## Affected endpoints (unauthenticated GET)\n\n- `GET /api/article`\n- `GET /api/comment`\n- `GET /api/file`\n- `GET /api/page`\n- `GET /api/Knowledge`\n\n## Affected code\n\nVulnerable pattern in `findAll()` methods, including but not limited to:\n\n- `server/src/modules/article/article.service.ts`\n- `server/src/modules/comment/comment.service.ts`\n- `server/src/modules/file/file.service.ts`\n- `server/src/modules/page/page.service.ts`\n- `server/src/modules/knowledge/knowledge.service.ts`\n\n## Remediation\n\n- Whitelist allowed filter column names before interpolating into SQL.\n- Upgrade to `@fecommunity/reactpress` \u003e= 3.7.0.\n\n## Credit\n\nReported by lsr365400.","aliases":["CVE-2026-61685"],"modified":"2026-09-23T22:00:04.424651102Z","published":"2026-09-23T21:51:59Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-23T21:51:59Z","nvd_published_at":"2026-09-22T23:17:07Z","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/fecommunity/reactpress/security/advisories/GHSA-wmw4-mw6x-6vfm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61685"},{"type":"WEB","url":"https://github.com/fecommunity/reactpress/commit/78ecb70af1c021455c05fdcbe137212c70e310d6"},{"type":"PACKAGE","url":"https://github.com/fecommunity/reactpress"},{"type":"WEB","url":"https://github.com/fecommunity/reactpress/releases/tag/v3.7.0"}],"affected":[{"package":{"name":"@fecommunity/reactpress","ecosystem":"npm","purl":"pkg:npm/%40fecommunity/reactpress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.7.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.6.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wmw4-mw6x-6vfm/GHSA-wmw4-mw6x-6vfm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}