THREAT OPS › Threat News › [NVD] CVE-2026-78691 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an a
[NVD] CVE-2026-78691 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an a
CVE-2026-78691 CVSS: None Published: 2026-08-30T12:17:18.550
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an attacker-controlled pattern match.
The escape helpers in
Indicators of compromise
- CVE-2026-78691cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78691