CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name before creating some SQL statements (ALTER TABLE). So, in the application code, if the table name is provided by an untrusted upstream, it expose vulnerability to SQL injection when target schema change. This issue has been patched in version 0.3.34.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cocoindex-io
Cocoindex-io cocoindex |
|
| Vendors & Products |
Cocoindex-io
Cocoindex-io cocoindex |
Fri, 06 Mar 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name before creating some SQL statements (ALTER TABLE). So, in the application code, if the table name is provided by an untrusted upstream, it expose vulnerability to SQL injection when target schema change. This issue has been patched in version 0.3.34. | |
| Title | CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-06T06:39:08.934Z
Updated: 2026-03-06T16:06:07.600Z
Reserved: 2026-02-27T15:54:05.139Z
Link: CVE-2026-28438
Updated: 2026-03-06T16:00:08.876Z
Status : Received
Published: 2026-03-06T07:15:58.770
Modified: 2026-03-06T07:15:58.770
Link: CVE-2026-28438
No data.