@vendure/core has a SQL Injection vulnerability
Published Apr 21, 2026
9.1
CRITICALCVSS 3.1
EPSS 2.20%
Description
Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database. This affects all supported database backends (PostgreSQL, MySQL/MariaDB, SQLite). The Admin API is also affected, though exploitation there requires authentication. Versions 2.3.4, 3.5.7, and 3.6.2 contain a patch. For those who are unable to upgrade immediately, Vendure has made a hotfix available that uses `RequestContextService.getLanguageCode` to validate the `languageCode` input at the boundary. This blocks injection payloads before they can reach any query. The hotfix replaces the existing `getLanguageCode` method in `packages/core/src/service/helpers/request-context/request-context.service.ts`. Invalid values are silently dropped and the channel's default language is used instead. The patched versions additionally convert the vulnerable SQL interpolation to a parameterized query as defense in depth.
Affected products
-
- Version >= 1.7.4, < 2.3.4StatusaffectedConstraints-
- Version >= 3.0.0, < 3.5.7StatusaffectedConstraints-
- Version >= 3.6.0, < 3.6.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
@vendure/core
npm
Introduced 3.0.0 Fixed 3.5.7@vendure/core
npm
Introduced 3.6.0 Fixed 3.6.2@vendure/core
npm
Introduced 1.7.4 Fixed 2.3.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @vendure/core | 3.0.0 | 3.5.7 |
| npm | @vendure/core | 3.6.0 | 3.6.2 |
| npm | @vendure/core | 1.7.4 | 2.3.4 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 22, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.20% (0.02202) | 81.89th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.76% (0.01762) | 75.04th | v5 (v2026.06.15) |
| Jun 2, 2026 | 7.70% (0.07704) | 92.05th | v4 (v2025.03.14) |
| May 23, 2026 | 5.83% (0.05826) | 90.64th | v4 (v2025.03.14) |
| Apr 22, 2026 | 4.56% (0.04561) | 89.22th | v4 (v2025.03.14) |
References (3)
- https://github.com/advisories/GHSA-9pp3-53p2-ww9v Advisory
- https://github.com/vendurehq/vendure/security/advisories/GHSA-9pp3-53p2-ww9v x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-40887
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-9pp3-53p2-ww9v | Advisory | |
| https://github.com/vendurehq/vendure/security/advisories/GHSA-9pp3-53p2-ww9v | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40887 |
Change history (0)
No recorded changes yet.