Executive brief
asyncmy is a Python library used for fast, asynchronous connections to MySQL databases. A security flaw allows attackers to perform SQL injection by using specially crafted dictionary keys in database queries. This could lead to unauthorized access to sensitive data, modification of database records, or a complete compromise of the database server.
Technical details
A SQL injection vulnerability exists in asyncmy through version 0.2.11 due to improper neutralization of special elements used in SQL commands (CWE-89). The root cause is the library's failure to properly sanitize or quote dictionary keys when they are used to construct SQL queries. An attacker can exploit this by providing crafted dictionary keys that contain malicious SQL syntax. This is a network-reachable vulnerability that requires no authentication or user interaction, potentially allowing for full database takeover. As of the advisory date, no patched version has been identified.
Affected products
- long2ice asyncmy <= 0.2.11
Timeline
- 2025-12-02: advisory: GitHub Advisory published
- 2025-12-02: disclosed: NVD publication date