Disclosure summary
### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. ### Details **`coordinator/handlers/statistics_v4.go` lines 74-107** — `V4StatisticsQuery`: ```go query := &model.V4StatisticsQuery{} if err = c.Bind(query); err != nil { ... } // No ValidateRawSQL call here — contrast with other handlers: results, err := h.flightService.Query(c.Request().Context(), query.RawQuery) ``` **Contrast with `coordinator/handlers/search.go` line 194** — secure pattern not followed: ```go if err := sqlvalidator.ValidateRawSQL(rawQuery); err != nil { return c.JSON(http.StatusBadRequest, ...) } ``` `query.RawQuery` is whatever the caller submitted; it is passed verbatim to the FlightSQL/DuckDB backend. The handler is registered under the `protected` group (requires JWT), but given that the default JWT secret is empty (see related advisory), this is effectively pre-authentication on a default deployment. ### PoC ```bash # With a valid JWT (
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-f46q-3v67-fmm4
Open original source · Updated Oct 07, 2026
Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/sipcapture/homer-app | < 0.0.0-20260625085520-a7d027dc684b | 0.0.0-20260625085520-a7d027dc684b |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:13:08-04:00
MODIFIED 2026-10-07T12:13:09-04:00
INGESTED 2026-10-08T12:05:11-04:00