Vendure Core - SQL Injection
CVE-2026-40887
Verified
Description
Vendure, an open-source headless commerce platform built on Node.js/TypeScript, contains a critical SQL injection vulnerability in its Shop API. The languageCode query parameter is interpolated directly into a raw SQL CASE expression in ProductService.findOneBySlug without parameterization or input validation, allowing unauthenticated attackers to execute arbitrary SQL commands. This can lead to full database disclosure and denial of service.
Severity
Critical
CVSS Score
9.1
Exploit Probability
2%
Published Date
April 17, 2026
Template Author
theamanrawat
CVE-2026-40887.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVE ID:
cve-2026-40887
CWE ID:
cwe-89
Remediation Steps
Upgrade @vendure/core to version 3.6.2, 3.5.7, or 2.3.4 or later, which add input validation and parameterized queries for the languageCode parameter.