THREAT OPS › Threat News › [GHSA] GHSA-3496-9g83-7v6x (medium) — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
[GHSA] GHSA-3496-9g83-7v6x (medium) — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
GHSA-3496-9g83-7v6x Severity: medium CVE: CVE-2026-59894
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
### Summary
The documented Python and PHP output modes generate source-code snippets from caller-supplied SQL. Their output filters escape quote characters without first escaping existing backslashes. Crafted SQL can therefore neutralize th
Indicators of compromise
- CVE-2026-59894cve
Original source: https://github.com/advisories/GHSA-3496-9g83-7v6x