Two disclosed SQL injection vulnerabilities affect Saltcorn and Dagster, allowing authenticated users to execute unintended database queries and access data beyond their assigned privileges. In Saltcorn, the flaw in mobile sync endpoints can bypass application-level authorization controls to extract arbitrary table contents, including sensitive records from _sc_config and bcrypt password hashes from the users table. The exposure can also include active administrative session identifiers in some deployments, creating a direct path to account takeover.
The impact extends beyond data exposure in several configurations. Saltcorn deployments using PostgreSQL may permit stacked queries, enabling attackers to run DML or DDL statements that delete tables, alter configuration, and escalate from a low-privileged account to full administrative control. In Dagster, injected SQL runs with the privileges assigned to the platform's database credentials, which often include broad read, write, and delete access to warehouse data. The risk is particularly acute in Dagster OSS, where limited RBAC means users with API access may be able to trigger the flaw, while Dagster+ reduces default exposure but can still permit privilege escalation under custom RBAC settings.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Dagster fixed the SQL injection vulnerability affecting dynamic partition keys in its DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers in Dagster Core 1.13.1 and Dagster libraries 0.29.1. The flaw affected deployments using dynamic partitions and required a user with the Add Dynamic Partitions permission to exploit.
Saltcorn released fixes for the mobile-sync SQL injection vulnerability in versions 1.4.6, 1.5.6, and 1.6.0-beta.5. The patched releases address an issue that allowed authenticated low-privilege users to inject SQL via sync parameters and potentially exfiltrate or modify database contents.
A SQL injection vulnerability in Dagster dynamic partitions was disclosed, with impact depending on the privileges of the database credentials used by the Dagster I/O manager. The disclosure noted risks of unauthorized data exposure, destructive modification, and possible privilege escalation, especially in Dagster OSS environments lacking granular RBAC.
A vulnerability affecting Saltcorn Mobile Sync endpoints was disclosed, describing how an authenticated attacker could bypass application-level authorization and use SQL injection to exfiltrate arbitrary database contents, including configuration data and password hashes. In PostgreSQL deployments, the issue could also permit stacked queries, enabling destructive changes and privilege escalation to full administrative control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.