Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-108474: JetBrains Exposed can let attackers run unwanted database commands
CVE-2026-108474 · published today
Summary
The Exposed library for Kotlin may treat certain text inputs as code, allowing a cyber attacker to insert their own database commands. This could let them read, change, or delete data stored in your database. Update to version 1.5.1 or later, or apply the recommended code changes to properly escape input strings.
What to do
- Update jetbrains exposed to version 1.5.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jetbrains | exposed | < 1.5.1 |
Original advisory text
In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Type
CWE-89SQL Injection
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen9 Oct 2026
Track software like this
Free during beta