CVE-2026-33468Disclosure(kysely / kysely)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by doubling them (`'` → `''`) but does not escape backslashes. When used with the MySQL dialect (where `NO_BACKSLASH_ESCAPES` is OFF by default), an attacker can use a backslash to escape the trailing quote of a string literal, breaking out of the string context and injecting arbitrary SQL. This affects any code path that uses `ImmediateValueTransformer` to inline values — specifically `CreateIndexBuilder.where()` and `CreateViewBuilder.as()`. Version 0.28.14 contains a fix.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kysely

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
kysely

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-26: 3Technical Details · 2026-03-26: 303-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-33468 Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by do… https://www.cve.org/CVERecord?id=CVE-2026-33468 ----- Traducción: CVE-2026-33468 Kys… http://infoflow.cloud`

    Post summary

    CVE-2026-33468 points to a missing escape routine in Kysely’s SQL sanitizer; the post provides a brief technical detail but no PoC, exploit, patch, or active exploitation evidence.

    0000044
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33468 Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by do… https://www.cve.org/CVERecord?id=CVE-2026-33468

    Post summary

    The post discloses a missing single‑quote escaping vulnerability in Kysely’s query compiler before version 0.28.14, providing technical details but no PoC, exploit, patch, or active exploitation evidence.

    00000265
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33468 - High Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by doubling them (`'` → `''`... https://www.thehackerwire.com/vulnerability/CVE-2026-33468/ https://t.co/wMxfgLeFnL

    Post summary

    The tweet announces a high‑severity CVE in Kysely’s string sanitization logic before patch 0.28.14, offering a technical overview without indicating exploitation details or a patch.

    0000033
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkyselykysely-node.js-

Explore more