RUSTSEC-2026-0136
Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
Details
Diesel allows users to configure various options for PostgreSQL's `COPY FROM` and `COPY TO` statements. These configurations are partially provided as strings or characters.
Diesel did not check if any these user-provided options contain a quote character `'`, which can lead to the injection of additional options in the current `COPY FROM`/`COPY TO` statement.
This vulnerability affects any user of `COPY FROM`/`COPY TO` that passes user-provided input to any of the affected functions. It can result in modifications of options in the current statement, but it is not possible inject additional statements.
## Mitigation
The preferred mitigation to the outlined problem is to update to Diesel version 2.3.8 or newer, which includes fixes for the problem.
## Resolution
Diesel now correctly escapes any quotes contained in the provided arguments.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 2.3.8Upgrade diesel to 2.3.8 or newer (ecosystem crates.io).