Executive brief
Metacat is a data repository used by researchers to store and share scientific data. A security flaw in its registration component allows unauthorized individuals to run malicious database commands over the network. This could lead to the theft of sensitive research data, exposure of user credentials, or complete deletion of the repository's database.
Technical details
An unauthenticated SQL injection vulnerability exists in Metacat 2.x within the HarvesterRegistration.dbInsert() method. The application uses string concatenation with a flawed quoteString() helper that fails to escape single quotes when building INSERT statements against the HARVEST_SITE_SCHEDULE table. Attackers can inject malicious SQL via the 'unit', 'contactEmail', or 'documentListURL' parameters. Because the underlying PostgreSQL backend supports stacked queries, this allows for full read, write, and execute permissions within the database context. The vulnerability was addressed in version 3.0.0 by removing the affected harvesterClient package.
Affected products
- NCEAS Metacat 2.0.0 to 2.19.1
Timeline
- 2026-06-15: advisory: NVD publication date
- 2026-05-27: disclosed: GitHub Security Advisory published