PT-2026-94026 · Maarten · Marten

CVE-2026-75513

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Marten versions 7.0.0 through 9.12.0
Description Several paths within the LINQ provider and tenant-management internals interpolate runtime strings into single-quoted SQL literals without proper escaping or parameterization. This allows an attacker to use a crafted single quote to escape the literal and inject arbitrary SQL. This can lead to filter bypass, multi-tenant authorization bypass (allowing access to other tenants' data), and blind data exfiltration. In environments where semicolon-batched Npgsql statements are permitted, data modification is also possible.
Technical details include the following affected components:
  • The primary vector is the dictionary indexer key used in Where filters within DictionaryItemMember.cs.
  • DictionaryContainsKeyFilter.cs is affected when using the Newtonsoft serializer (System.Text.Json is not affected) during ContainsKey calls.
  • SelectParser.cs is affected when a constant string is projected via Select().
  • DeleteAllForTenant.cs is affected when a tenant ID is passed through IEventStore.DeleteProjectionProgressAsync().
  • DatabaseScopedTenantPartitions.cs is affected by tenant IDs inlined into partition DDL.
  • EventLoader.cs contains a defense-in-depth sink related to per-tenant partition-pruning literals.
Recommendations Update Marten to version 9.13.0. As a temporary workaround, avoid passing untrusted input as a dictionary indexer key, ContainsKey argument, Select constant, or as a tenant ID during projection teardown or provisioning. Disable multi-statement command batching to limit the potential impact of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75513
GHSA-RFX3-98H7-V3XP

Affected Products

Marten