THREAT OPS › Threat News › [GHSA] GHSA-rfx3-98h7-v3xp (critical) — Marten's LINQ provider has SQL injection via unescaped string literals
[GHSA] GHSA-rfx3-98h7-v3xp (critical) — Marten's LINQ provider has SQL injection via unescaped string literals
GHSA-rfx3-98h7-v3xp Severity: critical CVE: CVE-2026-75513
Marten's LINQ provider has SQL injection via unescaped string literals
Several code paths in Marten's LINQ provider and tenant-management internals interpolated a runtime, potentially attacker-influenced value into generated SQL as a single-quoted string literal without escaping or parameterization. A value containing a single quote (`'`
Indicators of compromise
- CVE-2026-75513cve
Original source: https://github.com/advisories/GHSA-rfx3-98h7-v3xp