CVE-2026-28438Disclosure(cocoindex / cocoindex)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name before creating some SQL statements (ALTER TABLE). So, in the application code, if the table name is provided by an untrusted upstream, it expose vulnerability to SQL injection when target schema change. This issue has been patched in version 0.3.34.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cocoindex

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
cocoindex

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-11: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-11: 103-0603-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure2
2026-03-111
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28438 (CVSS:6.9, CRITICAL) is Analyzed. CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t..https://nvd.nist.gov/vuln/detail/CVE-2026-28438 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑28438, noting its CVSS score and a vulnerability in the Doris target connector of CocoIndex; no PoC, exploit, patch, or active exploitation is referenced.

    0000057
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28438 CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name before creating some … https://www.cve.org/CVERecord?id=CVE-2026-28438

    Post summary

    CVE-2026-28438 is a disclosed vulnerability in CocoIndex's Doris target connector, where insufficient table name validation could allow unintended creation of objects. No PoC, exploit, patch, or active exploitation details are provided.

    00000145
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28438 SQL Injection in CocoIndex Data Transformation Framework Before 0.3.34 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28438

    Post summary

    The post announces a SQL injection vulnerability in CocoIndex Data Transformation Framework versions prior to 0.3.34, providing basic technical details but no exploitation proof or patch information.

    0000040
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcocoindexcocoindex---

Explore more