Vulnerability GHSA-r8cr-4f9w-7r75
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
September 15, 2026 at 07:48 PM UTC
Netmaker has a boolean‑based SQL Injection
v0.5.5 - v1.4.0
v0.5.5 - v1.4.0
Summary
Netmaker has a boolean‑based SQL Injection
Details
SQL Injection in Netmaker SQLite Database Backend
Summary
The sqliteDeleteRecord function in Netmaker's database layer constructs SQL DELETE statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform boolean-based SQL injection.
Credit
Artem Danilov (Positive Technologies)
Daniil Satyaev (Independent)
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
Netmaker does not verify JWT signatures for host tokens in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-5588
v0.5.5 - v1.4.0 GO-2026-5588
High Risk
4 months ago
Netmaker does not verify JWT signatures for host tokens
v0.5.5 - v1.4.0 GHSA-qpv2-rwc8-c993
v0.5.5 - v1.4.0 GHSA-qpv2-rwc8-c993
Unknown
6 months ago
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4651
v0.5.5 - v1.4.0 GO-2026-4651
Unknown
6 months ago
Netmaker has Privilege Escalation from Admin to Super-Admin via User Update in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4654
v0.5.5 - v1.4.0 GO-2026-4654
Unknown
6 months ago
Netmaker has Insufficient Authorization in Host Token Verification in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4655
v0.5.5 - v1.4.0 GO-2026-4655
Impacted packages
Timeline
Published
3 hours ago
September 15, 2026 at 07:48 PM UTC
Last Modified
3 hours ago
September 15, 2026 at 08:00 PM UTC