CRITICAL9.8
PYSEC-2026-489
SQLAlchemyDA unauthenticated arbitrary SQL query execution
Quick fix
PYSEC-2026-489 — products-sqlalchemyda: upgrade to the fixed version with the command below.
pip install --upgrade 'products-sqlalchemyda>=2.2'Details
### Impact The vulnerability allows unauthenticated execution of arbitrary SQL statements on the database the SQLAlchemyDA instance is connected to. All users are affected.
### Patches The problem has been patched in version 2.2.
### Workarounds There is no workaround. All users are urged to upgrade to version 2.2
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/products-sqlalchemyda
Introduced in:
0Fixed in: 2.2Fix
pip install --upgrade 'products-sqlalchemyda>=2.2'References
- https://github.com/zopefoundation/Products.SQLAlchemyDA/security/advisories/GHSA-r3jc-3qmm-w3pw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-24811[ADVISORY]
- https://github.com/zopefoundation/Products.SQLAlchemyDA/commit/e682b99f8406f20bc3f0f2c77153ed7345fd215a[WEB]
- https://github.com/zopefoundation/Products.SQLAlchemyDA[PACKAGE]
- https://pypi.org/project/products-sqlalchemyda[PACKAGE]
- https://github.com/advisories/GHSA-r3jc-3qmm-w3pw[ADVISORY]