CRITICAL9.8
PYSEC-2026-426
Mocodo vulnerable to SQL injection in `/web/generate.php`
Quick fix
PYSEC-2026-426 — mocodo: upgrade to the fixed version with the command below.
pip install --upgrade 'mocodo>=4.2.7'Details
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the `sql_case` input field in `/web/generate.php`, allowing remote attackers to execute arbitrary SQL commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-35374[ADVISORY]
- https://github.com/laowantong/mocodo/commit/f9368df28518b6c4a92fd207c260f1978ec34d6e[WEB]
- https://chocapikk.com/posts/2024/mocodo-vulnerabilities[WEB]
- https://github.com/laowantong/mocodo[PACKAGE]
- https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158[WEB]
- https://pypi.org/project/mocodo[PACKAGE]
- https://github.com/advisories/GHSA-j6cv-98jx-mrwr[ADVISORY]