PT-2026-94026 · Maarten · Marten
CVE-2026-75513
·
Published
2026-09-16
·
Updated
2026-09-19
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Marten versions 7.0.0 through 9.12.0
Description
Several paths within the LINQ provider and tenant-management internals interpolate runtime strings into single-quoted SQL literals without proper escaping or parameterization. This allows an attacker to use a crafted single quote to escape the literal and inject arbitrary SQL. This can lead to filter bypass, multi-tenant authorization bypass (allowing access to other tenants' data), and blind data exfiltration. In environments where semicolon-batched Npgsql statements are permitted, data modification is also possible.
Technical details include the following affected components:
- The primary vector is the dictionary indexer
keyused inWherefilters withinDictionaryItemMember.cs. DictionaryContainsKeyFilter.csis affected when using the Newtonsoft serializer (System.Text.Json is not affected) duringContainsKeycalls.SelectParser.csis affected when a constant string is projected viaSelect().DeleteAllForTenant.csis affected when a tenant ID is passed throughIEventStore.DeleteProjectionProgressAsync().DatabaseScopedTenantPartitions.csis affected by tenant IDs inlined into partition DDL.EventLoader.cscontains a defense-in-depth sink related to per-tenant partition-pruning literals.
Recommendations
Update Marten to version 9.13.0.
As a temporary workaround, avoid passing untrusted input as a dictionary indexer key,
ContainsKey argument, Select constant, or as a tenant ID during projection teardown or provisioning.
Disable multi-statement command batching to limit the potential impact of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marten