Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-40906 — AI Deep Analysis Summary

CVSS 10.0 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Electric SQL Engine has a **SQL Injection** flaw in the `/v1/shape` API's `order_by` parameter.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: **CWE-89** (SQL Injection). The flaw stems from **improper validation** of the `order_by` parameter, allowing raw SQL expressions to be injected directly into queries without sanitization.

Q3Who is affected? (Versions/Components)

📦 **Affected**: **Electric SQL** (Postgres real-time sync engine). Specifically versions **1.1.12** up to (but not including) **1.5.0**. 📉 **Vendor**: electric-sql.

Q4What can hackers do? (Privileges/Data)

🕵️ **Attacker Capabilities**: Any **authenticated user** can exploit this. They gain the ability to **read**, **write**, and **destroy** all data in the underlying PostgreSQL database.…

Q5Is exploitation threshold high? (Auth/Config)

🔓 **Threshold**: **Low** for exploitation, but **Medium** for access. Requires **Low Complexity** (AC:L) and **No User Interaction** (UI:N).…

Q6Is there a public Exp? (PoC/Wild Exploitation)

🧪 **Public Exploit**: **No**. The `pocs` field is empty. While advisory links exist, there is no confirmed public Proof-of-Concept (PoC) or wild exploitation code available yet.

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: Scan for Electric SQL instances running versions **1.1.12 - 1.4.x**. Check if the `/v1/shape` API endpoint is exposed and accepts `order_by` parameters.…

Q8Is it fixed officially? (Patch/Mitigation)

✅ **Fixed**: **Yes**. The vulnerability is patched in version **1.5.0** and later. 📝 **Reference**: See GitHub Advisory GHSA-h5rg-pxx7-r2hj and PR #4081 for the official fix details.

Q9What if no patch? (Workaround)

🛑 **No Patch Workaround**: If you cannot upgrade immediately, **restrict network access** to the `/v1/shape` API. Ensure strict **authentication controls** are in place.…

Q10Is it urgent? (Priority Suggestion)

⚡ **Urgency**: **HIGH**. CVSS Score indicates **Critical** impact (C:H, I:H, A:H). Since it allows full database destruction by authenticated users, patch to **v1.5.0+** immediately. 🏃‍♂️💨