
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28438 is a SQL injection vulnerability in the Doris target connector of CocoIndex, an open-source data transformation framework for AI applications. The vulnerability affects CocoIndex versions prior to 0.3.34 (specifically identified in version 0.3.28) and was published on March 6, 2026. It arises when the Doris connector constructs ALTER TABLE SQL statements without validating the configured table name, allowing injection if the table name originates from an untrusted upstream source. The CVSS v3.1 base score is 9.8 (Critical) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), classified as a classic SQL injection flaw. The Doris target connector in CocoIndex directly interpolates user-supplied table names into ALTER TABLE SQL statements during target schema change operations without any identifier validation or sanitization. Exploitation requires that the table name be sourced from an untrusted upstream (e.g., end-user input passed into the CocoIndex pipeline configuration), and the attack is network-accessible with no authentication or user interaction required. The fix in version 0.3.34 introduces validation of table names at the entry point, erroring out immediately if the name is not a valid SQL identifier (GitHub Advisory, Patch Commit).
Successful exploitation could allow an attacker to execute arbitrary SQL commands against the underlying Doris database, resulting in unauthorized data access (confidentiality breach), unauthorized data modification or deletion (integrity breach), and potential denial of service or database unavailability (availability impact). The vulnerability is particularly dangerous in multi-tenant or user-facing deployments of CocoIndex where table names may be dynamically supplied by end users, as it could expose the entire database to compromise. Given the network-accessible, unauthenticated nature of the attack vector, the blast radius extends to all data managed by the connected Doris instance (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.03%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on the application being configured to accept table names from untrusted sources, which limits the attack surface to specific deployment patterns (GitHub Advisory, Red Hat CVE).
legitimate_table; DROP TABLE sensitive_data; -- or a subquery to exfiltrate data.ALTER TABLE statement incorporating the unsanitized table name.ALTER TABLE statements with unexpected SQL syntax, semicolons, comment sequences (--, /**/), or subqueries embedded in table name fields; CocoIndex application logs showing errors related to unexpected SQL execution or schema change failures.Upgrade CocoIndex to version 0.3.34 or later, which validates table names at the entry point of the Doris target connector and rejects any name that is not a valid SQL identifier (GitHub Advisory, Patch Commit). As a workaround prior to patching, ensure all table names used to configure CocoIndex Doris targets originate from trusted, controlled sources (e.g., hardcoded string literals) rather than user-supplied input. If table names must come from external sources, implement strict allowlist validation (alphanumeric characters and underscores only) before passing them to the CocoIndex configuration. Additionally, restrict network access to the CocoIndex application and its Doris database connections to trusted hosts only.
The vulnerability was credited to researcher 4ur0n as the finder and was published as a GitHub Security Advisory (GHSA-59g6-v3vg-f7wc) by the CocoIndex maintainer georgeh0 on February 28, 2026. Red Hat tracked the issue in their CVE database. Community coverage was limited to automated CVE tracking feeds and security aggregators, with no significant broader media or researcher commentary observed (GitHub Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."