Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2025-09-12
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
High
resolved

SQL injection in JSONField KeyTransform


Bug reported by Eyal Gabay was disclosed at September 12, 2025, 12:28 am   |   SQL Injection

A vulnerability was discovered in the JSONField KeyTransform functionality of Django. The vulnerability allowed SQL injection attacks by crafting malicious user input for the .values() method. The vulnerability was demonstrated in the Django test suite, where a SQL syntax error was triggered by inputting a specifically crafted string.