MEDIUM6.5
PYSEC-2026-1855
python-sql SQL injection vulnerability
Quick fix
PYSEC-2026-1855 — python-sql: upgrade to the fixed version with the command below.
pip install --upgrade 'python-sql>=1.5.2'Details
A vulnerability was found in python-sql where unary operators do not escape non-Expression (like `And` and `Or`) which makes any system exposing those vulnerable to an SQL injection attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-9774[ADVISORY]
- https://access.redhat.com/security/cve/CVE-2024-9774[WEB]
- https://bugs.tryton.org/python-sql/93[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2332734[WEB]
- https://discuss.tryton.org/t/security-release-for-issue-93/7889[WEB]
- https://discuss.tryton.org/t/security-release-for-issue-93/7889/3[WEB]
- https://foss.heptapod.net/tryton/python-sql/-/commit/f20551bbb8b3b4c4dd0a2c3d36f377bff6f2f349[WEB]
- https://github.com/tryton/python-sql[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2024/10/msg00023.html[WEB]
- https://pypi.org/project/python-sql[PACKAGE]
- https://github.com/advisories/GHSA-pq9p-pc3p-9hm4[ADVISORY]