Hunting Orm And Query Builder Injection

Hunt injection that survives an object-relational mapper or query builder: untrusted input reaching a raw-query escape hatch, an unparameterizable identifier (a column, table, or sort order), or a structured filter or update object whose keys become query operators or column references. Covers raw-query methods that take a string or fragment, sort and column selectors taken from the request, and operator injection where a request body passed as a filter turns a comparison always-true or references a field it should not. Use when data access goes through an ORM or query builder and untrusted input reaches a raw method, an identifier argument, or a filter or update object rather than a bound value. The untrusted value that becomes query structure is the source, the data-access call is the sink, and the missing allowlist between them is the bug.

UnboundCompute bfa954f 9.0 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-orm-and-query-builder-injection commit bfa954f88f

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-orm-and-query-builder-injection