stigmem vulnerability

stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, request, or user input. Fixed in 0.9.0a2, which adds identifier quoting and validation. As a workaround, only configure schema names from trusted deployment configuration.

Published 19 Aug 2026Updated 11 Sep 20262 sources
CVSS 7.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.