ekuiper
Lightweight data stream processing engine for IoT edge
Activity
- Latest release
- 5d ago
- Total releases
- 72
- Cadence
- ~21 days
- Last 12 months
- 7
Reach
- Stars
- 1.7k
Details
- License
- Apache-2.0
- First release
- Dec 02, 2021
| Version | Released | |
|---|---|---|
2.4.2
patch
| ||
2.4.1
patch
| ||
2.4.0
minor
| ||
2.2.5
patch
| ||
2.2.4
patch
| ||
2.3.1
patch
| ||
2.3.0
minor
| ||
2.2.3
patch
| ||
2.2.2
patch
| ||
2.2.1
patch
| ||
2.1.5
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.0
minor
| ||
2.1.4
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.3
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.2
major
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.7
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.6
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.5
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.4
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.3
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.2
patch
1 CVE
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.1
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.14.0
minor
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.6
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.5
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.4
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.3
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.2
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.1
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.13.0
minor
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.8
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.7
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.6
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.5
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.4
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.3
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.2
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.1
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.12.0
minor
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.5
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.4
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.3
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.2
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.1
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.11.0
minor
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.2
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.1
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.0
minor
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.2
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.1
patch
2 CVEs
CVE-2025-54379
PYSEC-2025-241
GHSA-526j-mv3p-f4vv
GO-2025-3827
Jul 24, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the table name input in an API request. Exploitation can lead to data theft, corruption, or deletion, and full database compromise. This is fixed in version 2.2.1. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 127 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
2.1.2
2.1.3
2.1.4
2.1.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43406
GHSA-r5ph-4jxm-6j9p
GO-2024-3078
PYSEC-2024-72
Aug 20, 2024
LF Edge eKuiper has a SQL Injection in sqlKvStore
High
Network
Low
Low
None
SummaryA user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. DetailsI will use explainRuleHandler ("/rules/{name}/explain") as an example to illustrate. However, this vulnerability also exists in other methods such as sourceManageHandler, asyncTaskCancelHandler, pluginHandler, etc. The SQL injection can happen in the code: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L89-L93 The code to accept user input is: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/server/rest.go#L274-L277 The rule id in the above code can be used to exploit SQL query. Note that the delete function is also vulnerable: https://github.com/lf-edge/ekuiper/blob/d6457d008e129b1cdd54d76b5993992c349d1b80/internal/pkg/store/sql/sqlKv.go#L138-L141 PoC
The screenshot shows the malicious SQL query to insert a value:
The screenshot shows the breakpoint of executing the query:
ImpactSQL Injection vulnerability The reporters are Yuan Luo, Shuai Xiong, Haoyu Wang from Tencent YunDing Security Lab. Affected versions
0.0.1.post10035392509
0.0.1.post10469657945
0.0.1.post10592133245
0.0.1.post10917063435
0.0.1.post11433945270
0.0.1.post11434361037
0.0.1.post11771214162
0.0.1.post12369050331
0.0.1.post14569587727
0.0.1.post15011016639
0.0.1.post15265245754
0.0.1.post1529761077
+ 119 more Show less
0.0.1.post16017439871
0.0.1.post16212420887
0.0.1.post1640190752
0.0.1.post16436220442
0.0.1.post1656951467
0.0.1.post1661454534
0.0.1.post1707338123
0.0.1.post17425391204
0.0.1.post17934265679
0.0.1.post18767826745
0.0.1.post1926549727
0.0.1.post19563876430
0.0.1.post2080668443
0.0.1.post2238139389
0.0.1.post24644496127
0.0.1.post2474892687
0.0.1.post24975255951
0.0.1.post26427369374
0.0.1.post2757722354
0.0.1.post2910672767
0.0.1.post2911616762
0.0.1.post3144438011
0.0.1.post31763794892
0.0.1.post3239329472
0.0.1.post3334144675
0.0.1.post3334852441
0.0.1.post3410331757
0.0.1.post3411321026
0.0.1.post34304345391
0.0.1.post3495668732
0.0.1.post3545948676
0.0.1.post3712037225
0.0.1.post3764011091
0.0.1.post3936265927
0.0.1.post3954842791
0.0.1.post4180521993
0.0.1.post4435707843
0.0.1.post4562358382
0.0.1.post4720014312
0.0.1.post5010322351
0.0.1.post5065833905
0.0.1.post5265725915
0.0.1.post5484225879
0.0.1.post5899657036
0.0.1.post6045113904
0.0.1.post6144238120
0.0.1.post6453363172
0.0.1.post6555916078
0.0.1.post6820182077
0.0.1.post7205401650
0.0.1.post7257106983
0.0.1.post7404344961
0.0.1.post7405252226
0.0.1.post7458781898
0.0.1.post7797037221
0.0.1.post7983964087
0.0.1.post8014428509
0.0.1.post8150341330
0.0.1.post8273699428
0.0.1.post8319707068
0.0.1.post8478752636
0.0.1.post8782256682
0.0.1.post8813247801
0.0.1.post8829897389
0.0.1.post9220188115
0.0.1.post9638601298
0.0.1.post9690215560
0.0.1.post9736400841
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.14.0
1.14.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.14.2
References
Updated Sep 10, 2026 · Source: OSV.dev |