CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-40906

Critical · CVSS 9.9

ElectricSQL (electric-sql/electric) — Error-based SQL injection via ORDER BY parameter

CVSS
9.9
nvd
EPSS
KEV
No
Class
other
CWE-89, CWE-89

Description

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORDER BY expressions. This vulnerability is fixed in 1.5.0.

Search profile — drives PoC discovery

Symbols order_by/v1/shapeORDER BYshape APIPostgres sync engine
Keywords CVE-2026-40906ElectricSQLelectric-sqlSQL injectionorder_byv1/shapeGHSA-h5rg-pxx7-r2hjElectricSQL shape API SQLierror-based SQL injection ORDER BY
Versions: 1.1.12 to < 1.5.0

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z