VDB
Sign up
HIGH7.5

GHSA-p72q-h37j-3hq7

dbt uses a SQLparse version with a high vulnerability

Quick fix

GHSA-p72q-h37j-3hq7 — dbt-core: upgrade to the fixed version with the command below.

pip install --upgrade 'dbt-core>=1.6.13'

Details

### Summary

Using a version of `sqlparse` that has a security vulnerability and no way to update in current version of dbt core. Snyk recommends using `sqlparse==0.5` but this causes a conflict with dbt. Snyk states the issues is a recursion error: `SNYK-PYTHON-SQLPARSE-6615674`.

### Details Dependency conflict error message: ```sh The conflict is caused by: The user requested sqlparse==0.5 dbt-core 1.7.10 depends on sqlparse<0.5 and >=0.2.3 ``` Resolution was to pin `sqlparse >=0.5.0, <0.6.0` in `dbt-core`, patched in 1.6.13 and 1.7.13.

### PoC From Snyk:

```python import sqlparse sqlparse.parse('[' * 10000 + ']' * 10000) ```

### Impact Snyk classifies it as high 7.5/10.

### Patches The bug has been fixed in [dbt-core v1.6.13](https://github.com/dbt-labs/dbt-core/releases/tag/v1.6.13) and [dbt-core v1.7.13](https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.13).

### Mitigations Bump `dbt-core` 1.6 and 1.7 dependencies to 1.6.13 and 1.7.13 respectively

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/dbt-core
Introduced in: 1.6.0Fixed in: 1.6.13
Fixpip install --upgrade 'dbt-core>=1.6.13'
PyPI/dbt-core
Introduced in: 1.7.0Fixed in: 1.7.13
Fixpip install --upgrade 'dbt-core>=1.7.13'

References