Executive brief
Saltcorn is an open-source low-code database application platform. A critical SQL injection vulnerability in its mobile synchronization features allows any authenticated user with table read access to execute arbitrary SQL commands, leading to complete database compromise including theft of admin credentials, secrets, and all application data.
Technical details
The vulnerability is a SQL injection flaw (CWE-89) in the mobile-sync routes (/sync/load_changes and /sync/deletes) in packages/server/routes/sync.js. User-controlled values from the request body (specifically req.body.syncInfos[tableName].maxLoadedId and timestamp-derived values) are interpolated directly into SQL template literals without parameterization or proper validation. While db.sqlsanitize() is used for identifier escaping, it does not protect against value-based SQL injection. An authenticated low-privilege user can inject arbitrary SQL expressions that escape the intended query logic and execute in the database context. The attack requires valid authentication and read access to at least one table. Successful exploitation enables full database exfiltration, credential theft, and potentially data modification or destruction depending on database backend permissions. Patches are available in versions 1.4.6, 1.5.6, and 1.6.0-beta.5.
Affected products
- Saltcorn Saltcorn All versions before 1.4.6, 1.5.0-beta.0 through 1.5.5, 1.6.0-alpha.0 through 1.6.0-beta.4
Timeline
- 2026-04-16: disclosed