Junglewise Threat Intelligence

CVE-2026-33442: Kysely MySQL SQL Injection via backslash escape bypass in JSON paths

CVE-2026-33442 · Severity: low · CVSS 3.1 · Published 2026-03-20

Technologies: kysely (npm). Vendors: npm.

Executive brief

Kysely is a popular TypeScript query builder for databases. A vulnerability in how it escapes special characters in JSON path queries allows attackers to inject arbitrary SQL on MySQL databases if user-controlled input is passed to JSON path methods. An attacker who can control which JSON keys are accessed could read, modify, or delete sensitive data from the database.

Technical details

The vulnerability is a SQL injection flaw in the sanitizeStringLiteral() method within Kysely's query compiler. When building JSON path expressions (e.g., via .key() or .at() methods), user input is wrapped in single quotes but the compiler only escapes single quotes by doubling them—it does not escape backslashes. On MySQL with the default BACKSLASH_ESCAPES mode, an attacker can inject a backslash before a single quote (e.g., \' OR 1=1) to break out of the string literal and inject arbitrary SQL. The attack requires non-type-safe usage of JSON path builder methods with user-controlled input, which is realistic in applications with dynamic JSON schema access. PostgreSQL and SQLite are unaffected. A patch is available in version 0.28.14 and later.

Affected products

  • Kysely Kysely 0.28.12-0.28.13

Timeline

  • 2026-03-20: disclosed
  • 2026-03-20: patched: Fix available in version 0.28.14 and later

References

Related threats