A critical SQL injection flaw tracked as CVE-2026-54658 was disclosed in @hypequery/clickhouse, the TypeScript semantic layer for ClickHouse. The vulnerability affects versions prior to 2.0.2 and stems from improper parameter escaping in the escapeValue() function, which escaped single quotes but failed to escape backslashes first. An attacker controlling query parameters could supply a trailing backslash to escape the closing quote in a ClickHouse string literal and inject arbitrary SQL, resulting in potential compromise of confidentiality, integrity, and availability.
The maintainers patched the issue in version 2.0.2 by escaping backslashes before single quotes and added tests covering trailing backslashes, multiple backslashes, mixed backslash-and-quote cases, and multi-parameter injection attempts. The fix was published in the project commit, release notes, and changelog, which urge users to upgrade immediately; the disclosure also credits Coby Geralnik (@astelia) for responsibly reporting the bug.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-28, CVE-2026-54658 was publicly listed as a high-severity SQL injection vulnerability affecting @hypequery/clickhouse versions prior to 2.0.2. The advisory described how a trailing backslash in controlled query parameters could break out of the closing quote and enable arbitrary SQL execution.
On 2026-06-08, Hypequery committed and released a fix for a SQL injection vulnerability in escapeValue() that failed to escape backslashes before single quotes. The patch updated the escaping logic, added tests for trailing-backslash and related injection cases, and urged users to upgrade to version 2.0.2.
The @hypequery/clickhouse 2.0.2 release credits Coby Geralnik (@astelia) with responsibly disclosing a SQL injection vulnerability in the package's parameter escaping logic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.