Sploitus

CVE-2026-59894

1 known exploit for CVE-2026-59894

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0.

Affected products
Sqlparse
CVSS 4.0
6.2 MEDIUM
Weakness
CWE-94
NVD status
Received
Published
2026-08-17
CVE-2026-59894 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-59894

Proof-of-concept code and exploit modules indexed by Sploitus