VDB
Sign up
—

PYSEC-2026-2417

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

Quick fix

PYSEC-2026-2417 — ckan: upgrade to the fixed version with the command below.

pip install --upgrade 'ckan>=2.10.10'

Details

### Impact

A vulnerability in `datastore_search_sql` allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information.

### Patches The issue has been patched in CKAN 2.10.10 and CKAN 2.11.5

### Workarounds Disable the DataStore SQL search (`ckan.datastore.sqlsearch.enabled = false`). Note that the SQL search is disabled by default.

### More information

As stated in the [documentation](https://docs.ckan.org/en/2.11/maintaining/configuration.html#ckan-datastore-sqlsearch-enabled), this action function has protections that offer some safety but are not designed to prevent all types of abuse. Depending on the sensitivity of private data in a project's DataStore and the likelihood of abuse of a consuming site, a developer may choose to disable this action function or restrict its use with a [`IAuthFunctions`](https://docs.ckan.org/en/2.11/extensions/plugin-interfaces.html#ckan.plugins.interfaces.IAuthFunctions) plugin.

### Credits

* Reported by Arvin Shivram of Brutecat Security

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ckan
Introduced in: 0Fixed in: 2.10.10
Fixpip install --upgrade 'ckan>=2.10.10'

References