CVE-2026-78691
Received Received - Intake

SQL Injection in Ash SQL via LIKE Wildcard Bypass

Vulnerability report for CVE-2026-78691, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: EEF

Description

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an attacker-controlled pattern match. The escape helpers in AshSql.Expr prefix % and _ with a backslash but never escape a backslash already present in the input. Because backslash is the default LIKE escape character, the escaping defeats itself: the input \% becomes the pattern fragment \\%, where \\ is a literal backslash and the attacker's % remains a live wildcard. The search value stays parameterized, so this is confined to the LIKE pattern grammar rather than full SQL. An attacker can widen matches to probe values, slip past a negated contains(...) guard, or crash the query with a trailing lone backslash. This issue affects ash_sql: from 0.1.1-rc.10 before 0.7.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ash-project ash_sql From 0.1.1-rc.10 (inc) to 0.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a LIKE wildcard injection flaw in the ash_sql library. It occurs when functions like contains/2, string_starts_with/2, or string_ends_with/2 improperly handle backslashes in user input. The escape helpers add backslashes to wildcards (%) and underscores (_) but fail to escape existing backslashes. This allows attackers to inject live SQL wildcards, turning literal substring searches into pattern matches they control.

Detection Guidance

Check if your system uses ash_sql versions between 0.1.1-rc.10 and 0.7.0. Run: grep -r "ash_sql" --include="*.ex" --include="*.exs" /path/to/project. Look for functions like contains/2, string_starts_with/2, or string_ends_with/2 in code. Test inputs with backslashes followed by wildcards (e.g., "\%" or "\_") to see if they alter query results unexpectedly.

Review database logs for LIKE pattern queries that include backslashes or unusual wildcard usage. Check for crashes or errors from trailing backslashes in search terms.

Impact Analysis

An attacker could widen search results beyond intended matches, bypass security checks like negated contains() guards, or crash database queries with a trailing backslash. This might lead to unauthorized data exposure or access control bypasses, though the impact is limited to LIKE pattern matching and does not allow full SQL injection.

Compliance Impact

This vulnerability could potentially lead to unauthorized data exposure or access control bypasses, which may violate compliance requirements for data protection and access controls in standards like GDPR or HIPAA. However, the limited exploitability and low CVSS score suggest minimal direct impact on compliance.

Mitigation Strategies

Upgrade ash_sql to version 0.7.1 or later immediately. Update dependencies in your project files (mix.exs for Elixir) and redeploy. If upgrading is not possible, review all uses of contains/2, string_starts_with/2, and string_ends_with/2 to ensure inputs are sanitized before passing to these functions.

Apply input validation to reject search terms containing backslashes or enforce strict escaping rules. Monitor queries for LIKE patterns with wildcards to detect exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78691. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart