PT-2026-95006 · Signoz+1 · Signoz+1
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SigNoz versions 0.88.0 through 0.142.0
Description
Authenticated attackers can execute arbitrary SQL queries and retrieve results in HTTP responses. This occurs because the trace-funnel analytics endpoints interpolate the
service name and span name fields into ClickHouse string literals without proper escaping.Recommendations
Update SigNoz to version 0.142.1.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clickhouse
Signoz