Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-wmw4-mw6x-6vfm CVE-2026-61685

SQL Injection in ReactPress API Endpoints via Unsanitized Query Parameter Names (CVE-2026-61685)

ReactPress versions up to and including 3.6.0 are vulnerable to unauthenticated SQL injection because API list endpoints use unsanitized HTTP query parameter names as SQL column identifiers in TypeORM query builders. Version 3.7.0 contains a fix.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A SQL injection vulnerability has been identified in ReactPress, a publishing system for React developers. The issue affects how certain API endpoints build database queries and can be exploited by unauthenticated attackers through specially crafted request parameters. A fixed version is available.

What happened

ReactPress API list endpoints construct TypeORM `QueryBuilder` conditions by inserting HTTP query parameter names directly into SQL as column identifiers (for example, in the pattern `article.${key}`). TypeORM parameterizes query values, but it does not parameterize column identifiers, so values that are meant to be used as query parameter keys can instead be crafted to inject SQL. This allows an unauthenticated attacker to influence the resulting SQL statement by sending crafted query string keys.

Technical cause

The root cause is improper neutralization of special elements used in SQL commands (CWE-89). Affected endpoints take the name of a query parameter from the incoming HTTP request and interpolate it directly into a SQL column reference used in a TypeORM `QueryBuilder` condition. Because TypeORM only parameterizes bound values and not identifiers such as column names, there is no automatic protection against malicious input placed in the parameter name itself.

Why it matters

The vulnerability has a CVSS base score of 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), reflecting that it can be exploited remotely over the network, requires no authentication, no user interaction, and has low attack complexity. The vector indicates a high impact on confidentiality, with no direct impact on integrity or availability as scored. This means an attacker could potentially extract sensitive data from the underlying database without needing valid credentials.

Affected versions

All versions of @fecommunity/reactpress from version 0 up to and including 3.6.0 are affected. Version 3.7.0 contains a patch that addresses this vulnerability.

Fixes and mitigation

Users should upgrade @fecommunity/reactpress to version 3.7.0, which contains a patch for this issue. As a temporary workaround, if upgrading is not immediately possible, administrators can allowlist the specific column names that are permitted to be used as filters before those names are interpolated into SQL queries, rather than accepting arbitrary parameter names from user input.

Recommended action

Site owners running @fecommunity/reactpress at version 3.6.0 or earlier should update to version 3.7.0 as soon as possible. Where immediate upgrading is not feasible, implement the documented column-name allowlist workaround to prevent unsanitized query parameter names from being used in SQL column identifiers.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Why this score

The PatchWire score of 4.9 is driven primarily by the CVSS base score of 7.5, which reflects a network-exploitable, low-complexity vulnerability requiring no authentication or user interaction, with a high confidentiality impact. Additional small contributions come from the unauthenticated/remote nature of the flaw and the absence of required user interaction. The score does not include any increase from known exploitation, public exploit availability, or EPSS data, as none of these factors were established as elevated in the fact package (EPSS percentage and percentile were recorded but reported as low, and known/public exploitation is marked false).

Affected versions

@fecommunity/reactpress <= 3.6.0
vulnerable
≥ 3.7.0
patched

Reported fixes

Users should upgrade @fecommunity/reactpress to version 3.7.0, which contains a patch for this issue. As a temporary workaround, if upgrading is not immediately possible, administrators can allowlist the specific column names that are permitted to be used as filters before those names are interpolated into SQL queries, rather than accepting arbitrary parameter names from user input.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
SQL Injection in ReactPress API Endpoints via Unsanitized Query Parameter Names (CVE-2026-61685)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email