CVE-2026-32763 is a high-severity SQL injection vulnerability impacting Kysely, a TypeScript SQL query builder, in versions up to 0.28.11. The flaw stems from improper handling of user-controlled input in JSON path compilation for MySQL and SQLite dialects, allowing attackers to inject arbitrary SQL commands. Rated 8.2 CVSS (High), this vulnerability has a network attack vector, low attack complexity, and requires no privileges or user interaction, potentially leading to high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.26.0, < 0.28.12CPE matchmatch criteria | cpe:2.3:a:kysely:kysely:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.