CVE-2026-41490 is a SQL injection vulnerability in Dagster affecting Dagster Core prior to 1.13.1 and Dagster libraries prior to 0.29.1. In the DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers, SQL WHERE clauses were built by directly interpolating dynamic partition key values into queries without proper escaping. An attacker or malicious user with permission to add dynamic partitions can supply a crafted partition key containing SQL syntax, causing arbitrary SQL to be executed by the target database backend using the credentials configured for the affected I/O manager. The issue only affects deployments that use dynamic partitions; static partitions and time-window partitions are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept for CVE-2026-41490, a SQL injection issue in Dagster database I/O managers when DynamicPartitionsDefinition is used. The repo contains two files: a README describing the vulnerability, attack chain, affected packages, and exploitation rationale; and a single Python PoC script at poc/poc_partition_sqli.py that serves as the main entry point. The exploit’s core capability is turning attacker-controlled dynamic partition keys into arbitrary SQL fragments because vulnerable Dagster I/O managers build WHERE clauses with direct f-string interpolation of partition values. The PoC demonstrates three layers: (1) direct reproduction of the vulnerable _static_where_clause logic to show how benign and malicious partition keys become unsafe SQL; (2) a live DuckDB exploitation demo that creates a temporary database, seeds normal and sensitive tables, and shows practical exfiltration/destructive impact; and (3) printed GraphQL attack payloads showing how an attacker would use Dagster’s /graphql endpoint with addDynamicPartition and launchRun mutations to deliver the malicious partition key in a realistic deployment. The attack vector is primarily network/web-based: an attacker with access to the Dagster webserver can submit GraphQL mutations, and the malicious partition key later flows into SELECT or DELETE statements executed against the backing warehouse. The repository does not implement a full remote exploit client against a live Dagster instance; instead it provides operational PoC logic and concrete payloads that can be adapted easily. Because it includes working SQL payload examples and a live database demonstration, it is more than a detection script and fits an OPERATIONAL PoC classification. Notable fingerprintable targets and artifacts include the /graphql endpoint, GraphQL operations addDynamicPartition and launchRun, example repository/job selector values (__repository__, __ASSET_JOB__), the temporary DuckDB file test.duckdb, and demo tables such as public.user_data and public.secret_credentials. Overall, the repository’s purpose is to validate exploitability, illustrate the vulnerable code path, and show how unauthenticated or exposed Dagster GraphQL access can be chained into SQL injection against multiple Dagster-supported database backends.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.