Executive brief
OpenCATS, an open-source applicant tracking system, contains a security flaw in how it handles data filters. An authorized user can bypass security restrictions to run unauthorized database commands. This could allow an attacker to view sensitive candidate information or modify database records, potentially compromising the integrity of the recruitment platform.
Technical details
An SQL injection vulnerability exists in OpenCATS starting from version 0.9.1a within the DataGrid filter handling component. The root cause is a failure to enforce 'filterable => false' restrictions on the server side for the 'Tags' column in the Candidates DataGrid. An authenticated attacker can manipulate filter requests to target this non-filterable column, bypassing intended restrictions to inject malicious SQL syntax. This allows for unauthorized data extraction or modification. While a patch has been described (skipping server-side processing for non-filterable columns), a specific patched version number was not confirmed in the advisory text.
Affected products
- OpenCATS OpenCATS >= 0.9.1a
Timeline
- 2026-04-23: advisory: GitHub Security Advisory published
- 2026-05-31: disclosed: NVD publication date