VDB
Sign up
CRITICAL9.8

PYSEC-2026-426

Mocodo vulnerable to SQL injection in `/web/generate.php`

Quick fix

PYSEC-2026-426 — mocodo: upgrade to the fixed version with the command below.

pip install --upgrade 'mocodo>=4.2.7'

Details

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the `sql_case` input field in `/web/generate.php`, allowing remote attackers to execute arbitrary SQL commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mocodo
Introduced in: 0Fixed in: 4.2.7
Fixpip install --upgrade 'mocodo>=4.2.7'

References