Skip to content

fix: add parameterized queries in Toolforge.js - #44

Merged
kanasimi merged 1 commit into
kanasimi:masterfrom
anupamme:fix-repo-cejs-toolforge-sql-injection-v001
Sep 17, 2026
Merged

kanasimi merged 1 commit into
kanasimi:masterfrom
anupamme:fix-repo-cejs-toolforge-sql-injection-v001

Conversation

@anupamme

Copy link
Copy Markdown
Contributor

Summary

Fix critical severity security issue in application/net/wiki/Toolforge.js.

Vulnerability

Field Value
ID V-001
Severity CRITICAL
Scanner multi_agent_ai
Rule V-001
File application/net/wiki/Toolforge.js:321
Assessment Likely exploitable
CWE CWE-89

Description: The create_database function constructs SQL queries using string concatenation with the dbname parameter. While there is a basic check for backtick characters, the database name is directly interpolated into the SQL query without proper parameterization, allowing potential SQL injection if the validation is bypassed or insufficient.

Evidence

Exploitation scenario: An attacker who can control the dbname parameter could attempt to inject SQL by: 1) Using Unicode variants of backticks that pass the includes('`') check but are interpreted as backticks by MySQL,.

Scanner confirmation: multi_agent_ai rule V-001 flagged this pattern.

Production code: This file is in the production codebase, not test-only code.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • application/net/wiki/Toolforge.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
@kanasimi
kanasimi merged commit f439f8d into kanasimi:master Sep 17, 2026
4 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants