CVE-2026-41422
High
Published: 07 May 2026
Published
07 May 2026
Modified
07 May 2026
KEV Added
—
Patch
—
CVSS Score
8.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
EPSS Score
0.0005
14.1th percentile
Risk Priority
17
60% EPSS · 20% KEV · 20% CVSS
Description
Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() — a raw SQL literal expression builder — without any validation. This bypassed all parameterization…
more
and allowed authenticated users with any valid session to inject arbitrary SQL expressions. This issue has been patched in version 0.11.4.
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Security SummaryAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)