AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-62251.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. ### Details **`coordinator/handlers/statistics_v4.go` lines 74-107** — `V4StatisticsQuery`: ```go query := &model.V4StatisticsQuery{} if err = c.Bind(query); err != nil { ... } // No ValidateRawSQL call here — contrast with other handlers: results, err := h.flightService.Query(c.Request().Context(), query.RawQuery) ``` **Contrast with `coordinator/handlers/search.go` line 194** — secure pattern not followed: ```go if err := sqlvalidator.ValidateRawSQL(rawQuery); err != nil { return c.JSON(http.StatusBadRequest, ...) } ``` `query.RawQuery` is whatever the caller submitted; it is passed verbatim to the FlightSQL/DuckDB backend. The handler is registered under the `protected` group (requires JWT), but given that the default JWT secret is empty (see related advisory), this is effectively pre-authentication on a default deployment. ### PoC ```bash # With a valid JWT (

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-f46q-3v67-fmm4

Open original source · Updated Oct 07, 2026

Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/sipcapture/homer-app< 0.0.0-20260625085520-a7d027dc684b0.0.0-20260625085520-a7d027dc684b

Original records & references

PUBLISHED 2026-10-07T12:13:08-04:00
MODIFIED 2026-10-07T12:13:09-04:00
INGESTED 2026-10-08T12:05:11-04:00