THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r8cr-4f9w-7r75 (medium) — Netmaker has a boolean‑based SQL Injection

[GHSA] GHSA-r8cr-4f9w-7r75 (medium) — Netmaker has a boolean‑based SQL Injection

medgithub_advisoriesPublished 2026-09-15

GHSA-r8cr-4f9w-7r75 Severity: medium CVE: CVE-2026-32599

Netmaker has a boolean‑based SQL Injection

# SQL Injection in Netmaker SQLite Database Backend

## Summary

The `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform **boolean-based SQL injectio

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r8cr-4f9w-7r75