{"schema_version":"1.7.3","id":"GHSA-q97m-8853-pq76","published":"2025-05-16T15:31:02Z","modified":"2026-02-04T04:26:06.308371Z","aliases":["BIT-seaweedfs-2024-40120","CVE-2024-40120","GO-2025-3690"],"related":["CGA-437m-96hr-h87g"],"summary":"SeaweedFS Vulnerable to SQL Injection","details":"seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.","affected":[{"package":{"name":"github.com/seaweedfs/seaweedfs","ecosystem":"Go","purl":"pkg:golang/github.com/seaweedfs/seaweedfs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20240625155419-9ac102336200"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40120"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/issues/5710"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/commit/9ac1023362000f6e8e58c9d278653f5926a0d90e"},{"type":"WEB","url":"https://gist.github.com/sud0why/1b2115c1d644bd3db1c1b3f16684a78c"},{"type":"PACKAGE","url":"https://github.com/seaweedfs/seaweedfs"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/releases/tag/3.69"}],"database_specific":{"cwe_ids":["CWE-89"],"github_reviewed":true,"github_reviewed_at":"2025-05-16T21:59:34Z","nvd_published_at":"2025-05-16T13:15:51Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}