
`Kysely` has a MySQL SQL Injection via Backslash Escape Bypass (CVE-2026-33442). Attackers could execute arbitrary SQL. Review `Kysely` usage with MySQL for non-type-safe JSON path keys. #SQLi #Kysely #InfoSec https://www.pulsepatch.io/posts/cve-2026-33442-kysely-mysql-sql-injection
Post summary
Kysely is vulnerable to a MySQL SQL injection via backslash escape bypass (CVE‑2026‑33442), allowing attackers to execute arbitrary SQL. No proof of concept, exploit code, patch, or active exploitation details are provided.



