Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wc3v-3457-c8cm | OpenMeter: SQL injection through meter creation |
| Link | Providers |
|---|---|
| https://github.com/openmeterio/openmeter/pull/4383 |
|
Wed, 16 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API. | |
| Title | OpenMeter SQL Injection in ClickHouse-backed Meter Definitions | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Kong
Published:
Updated: 2026-09-16T17:46:37.602Z
Reserved: 2026-05-13T10:00:57.228Z
Link: CVE-2026-8462
Updated: 2026-09-16T17:46:26.173Z
Status : Received
Published: 2026-09-16T11:17:11.327
Modified: 2026-09-16T18:17:19.157
Link: CVE-2026-8462
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Github GHSA