THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rfx3-98h7-v3xp (critical) — Marten's LINQ provider has SQL injection via unescaped string literals

[GHSA] GHSA-rfx3-98h7-v3xp (critical) — Marten's LINQ provider has SQL injection via unescaped string literals

medgithub_advisoriesPublished 2026-09-17

GHSA-rfx3-98h7-v3xp Severity: critical CVE: CVE-2026-75513

Marten's LINQ provider has SQL injection via unescaped string literals

Several code paths in Marten's LINQ provider and tenant-management internals interpolated a runtime, potentially attacker-influenced value into generated SQL as a single-quoted string literal without escaping or parameterization. A value containing a single quote (`'`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rfx3-98h7-v3xp