Two high-severity SQL injection vulnerabilities were disclosed in Kysely, the TypeScript SQL query builder, affecting versions 0.28.12 and 0.28.13 in one case and versions prior to 0.28.14 in another. Both flaws stem from improper handling of backslashes in DefaultQueryCompiler.sanitizeStringLiteral(), which escaped single quotes but did not escape backslashes. In MySQL deployments using the default backslash-escape behavior, an attacker could place a backslash before a quote, break out of a string literal or JSON path string, and inject arbitrary SQL. Both issues are tracked as CWE-89 and carry a CVSS 3.1 score vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.
The first issue, CVE-2026-33442, affects non-type-safe usage of JSON path keys, while CVE-2026-33468 impacts code paths that inline values into compiled SQL strings, including sql.lit(string)-style usage and components such as CreateIndexBuilder.where() and CreateViewBuilder.as() through ImmediateValueTransformer. GitHub security advisories were referenced for both disclosures, and the vendor fixed the vulnerabilities in Kysely 0.28.14, making upgrade the primary remediation for affected MySQL-backed applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Two CVEs were disclosed for Kysely covering related MySQL SQL injection scenarios: one involving non-type-safe JSON path key usage and another involving sql.lit(string) and similar inline string literal paths. Both advisories describe improper escaping of backslashes in sanitizeStringLiteral and reference a GitHub security advisory.
Kysely fixed SQL injection vulnerabilities caused by insufficient backslash escaping in string literal sanitization in version 0.28.14. The issues affected prior versions including 0.28.12 and 0.28.13 and could enable SQL injection in MySQL under default backslash-escape behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.