Junglewise Threat Intelligence

CVE-2025-29744: pg-promise SQL Injection in negative number handling

CVE-2025-29744 · Severity: low · CVSS 3.1 · Published 2025-06-12

Vendors: npm.

Executive brief

pg-promise is a Node.js library used by developers to interact with PostgreSQL databases. A SQL injection vulnerability in versions before 11.5.5 allows attackers to bypass query parameterization when handling negative numbers, potentially enabling unauthorized database access or manipulation. Applications using the affected versions could be compromised if they process untrusted numeric input without additional validation.

Technical details

pg-promise before version 11.5.5 contains a SQL injection vulnerability (CWE-89) caused by improper handling of negative numbers during query parameter processing. The vulnerability exploits a logic flaw where negative number parameters are not properly escaped or validated, allowing an attacker to inject arbitrary SQL code. The attack vector is network-based with no authentication required, though user interaction may be needed to trigger the vulnerability depending on application design. An attacker can achieve SQL injection leading to unauthorized data access, modification, or deletion. The vulnerability is fixed in version 11.5.5 and later.

Affected products

  • vitaly-t pg-promise before 11.5.5

Timeline

  • 2025-06-12: disclosed: GHSA advisory published
  • 2025-06-12: patched: Fix available in version 11.5.5

References