THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-78691 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an a

[NVD] CVE-2026-78691 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an a

mednvdPublished 2026-08-30

CVE-2026-78691 CVSS: None Published: 2026-08-30T12:17:18.550

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an attacker-controlled pattern match.

The escape helpers in

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78691