GHSA-jg26-q8hg-3pq4
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)
Quick fix
GHSA-jg26-q8hg-3pq4 — sulu/sulu: upgrade to the fixed version with the command below.
composer require sulu/sulu:^2.6.25Details
### Impact
An unauthenticated JCR-SQL2 injection exists in the Smart Content category filter of the 2.x content query builder.
Category IDs supplied through the public `?categories=` query parameter are only trimmed and are then concatenated directly into a JCR-SQL2 `WHERE` clause, without the numeric validation that the equivalent tag filter already performs. Any public page that renders a Smart Content element with category filtering enabled evaluates this parameter, so no authentication or special configuration beyond a category-filtered content block is required.
An anonymous visitor can therefore:
- inject boolean conditions to infer the existence of, and disclose, content nodes they should not see (for example unpublished pages) via blind boolean-based extraction; and - submit malformed query fragments that cause query errors or resource-intensive queries, degrading availability.
Because the sink is a JCR-SQL2 query, the impact is limited to reading and enumerating content-repository nodes and to error/denial-of-service conditions; it cannot be used to modify data through this path.
### Patches
Fixed in **2.6.25 and 3.0.8**. Category, tag, and audience-target-group IDs are now cast to integers before they are used in the JCR-SQL2 query, so no attacker-controlled characters can reach the query.
### Workarounds
If you cannot upgrade immediately:
- Apply the fix manually — cast each ID to an integer where it is concatenated into the category (and, defensively, tag and audience-targeting) `WHERE` clause in the content Smart Content query builder. - Alternatively, disable category filtering on publicly reachable Smart Content elements until the patch is applied.
Are you affected?
Enter the version of the package you're using.