Medium · 4.9 Node.js & npm GHSA-wmw4-mw6x-6vfm CVE-2026-61685
SQL Injection in ReactPress API Endpoints via Unsanitized Query Parameter Names (CVE-2026-61685)
ReactPress versions up to and including 3.6.0 are vulnerable to unauthenticated SQL injection because API list endpoints use unsanitized HTTP query parameter names as SQL column identifiers in TypeORM query builders. Version 3.7.0 contains a fix.
AI summary
A SQL injection vulnerability has been identified in ReactPress, a publishing system for React developers. The issue affects how certain API endpoints build database queries and can be exploited by unauthenticated attackers through specially crafted request parameters. A fixed version is available.
What happened
ReactPress API list endpoints construct TypeORM `QueryBuilder` conditions by inserting HTTP query parameter names directly into SQL as column identifiers (for example, in the pattern `article.${key}`). TypeORM parameterizes query values, but it does not parameterize column identifiers, so values that are meant to be used as query parameter keys can instead be crafted to inject SQL. This allows an unauthenticated attacker to influence the resulting SQL statement by sending crafted query string keys.
Technical cause
The root cause is improper neutralization of special elements used in SQL commands (CWE-89). Affected endpoints take the name of a query parameter from the incoming HTTP request and interpolate it directly into a SQL column reference used in a TypeORM `QueryBuilder` condition. Because TypeORM only parameterizes bound values and not identifiers such as column names, there is no automatic protection against malicious input placed in the parameter name itself.
Why it matters
The vulnerability has a CVSS base score of 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), reflecting that it can be exploited remotely over the network, requires no authentication, no user interaction, and has low attack complexity. The vector indicates a high impact on confidentiality, with no direct impact on integrity or availability as scored. This means an attacker could potentially extract sensitive data from the underlying database without needing valid credentials.
Affected versions
All versions of @fecommunity/reactpress from version 0 up to and including 3.6.0 are affected. Version 3.7.0 contains a patch that addresses this vulnerability.
Fixes and mitigation
Users should upgrade @fecommunity/reactpress to version 3.7.0, which contains a patch for this issue. As a temporary workaround, if upgrading is not immediately possible, administrators can allowlist the specific column names that are permitted to be used as filters before those names are interpolated into SQL queries, rather than accepting arbitrary parameter names from user input.
Recommended action
Site owners running @fecommunity/reactpress at version 3.6.0 or earlier should update to version 3.7.0 as soon as possible. Where immediate upgrading is not feasible, implement the documented column-name allowlist workaround to prevent unsanitized query parameter names from being used in SQL column identifiers.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Why this score
The PatchWire score of 4.9 is driven primarily by the CVSS base score of 7.5, which reflects a network-exploitable, low-complexity vulnerability requiring no authentication or user interaction, with a high confidentiality impact. Additional small contributions come from the unauthenticated/remote nature of the flaw and the absence of required user interaction. The score does not include any increase from known exploitation, public exploit availability, or EPSS data, as none of these factors were established as elevated in the fact package (EPSS percentage and percentile were recorded but reported as low, and known/public exploitation is marked false).
Affected versions
- @fecommunity/reactpress <= 3.6.0
- vulnerable
- ≥ 3.7.0
- patched
Reported fixes
Users should upgrade @fecommunity/reactpress to version 3.7.0, which contains a patch for this issue. As a temporary workaround, if upgrading is not immediately possible, administrators can allowlist the specific column names that are permitted to be used as filters before those names are interpolated into SQL queries, rather than accepting arbitrary parameter names from user input.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email