9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.
AI Analysis
SQL injection vulnerability in Marten's full-text search regConfig parameter
Basic Information
ID
CVE-2026-45288
Source
GitHub_M
Published
May 28, 2026 at 20:20
Affected Product
Vendor
JasperFx
Product
marten
Version
< 8.36.1
Affected Versions
JasperFx marten < 8.36.1
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
JasperFx
Product
Marten
Version
< 8.36.1