THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3496-9g83-7v6x (medium) — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

[GHSA] GHSA-3496-9g83-7v6x (medium) — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

medgithub_advisoriesPublished 2026-08-17

GHSA-3496-9g83-7v6x Severity: medium CVE: CVE-2026-59894

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

### Summary

The documented Python and PHP output modes generate source-code snippets from caller-supplied SQL. Their output filters escape quote characters without first escaping existing backslashes. Crafted SQL can therefore neutralize th

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3496-9g83-7v6x