
🚨Critical - JetBrains Exposed SQL Injection via Unescaped SQL Function Args (CVE-2026-108474) JetBrains Exposed < 1.5.1 allows SQLi where several SQL functions accept raw string arguments that aren’t escaped/parameterized. Crafted input passed into these function parameters can break out of the query context and execute attacker-controlled SQL, enabling data exfiltration/modification. Queries using bound parameters aren’t impacted. 👉Affected: JetBrains Exposed < 1.5.1 | Upgrade to 1.5.1

