CVE-2026-44635Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) — including type-safe code where the JSON column is shaped like Record<string, T> so K extends string is the inferred type — every dot becomes a path-leg separator, letting an attacker traverse from the intended key into sibling and child fields the developer never meant to expose. The result is read access (and, in update statements, write access) to JSON sub-fields outside the intended scope across MySQL, PostgreSQL ->$/->>$, and SQLite. This vulnerability is fixed in 0.28.17.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-89CWE-915CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-27: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-27: 105-1205-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulert@vulert_official
    Disclosure

    🚨 Critical Kysely Vulnerability — CVE-2026-44635 Attackers may access sensitive JSON data due to improper input handling ⚠️ 🔗 https://vulert.com/vuln-db/CVE-2026-44635 Vulert helps detect vulnerabilities in open-source dependencies #CyberSecurity #Kysely #CVE2026 #DevSecOps #SecurityAlert https://t.co/Ei5CBNGjmj

    Post summary

    A new critical vulnerability in Kysely (CVE-2026-44635) is disclosed, allowing attackers to read sensitive JSON data via improper input handling, with no exploit, patch, or active exploitation details provided.

    0000121
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44635 Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *… https://www.cve.org/CVERecord?id=CVE-2026-44635

    Post summary

    The post reports a JSON‑path escaping issue in Kysely (versions 0.26.0–0.28.16) that could expose a vulnerability. No exploit, patch, or evidence of active attacks is provided.

    00000144
    57.5K followersView on X

Explore more