Get real-time updates on Telegram
Verified
CVE-2026-106097: Code Snippets 0 to before 3.10.0
Affected technology
Code Snippets · 0 to before 3.10.0
Vendor not specified by the source
Description’s affected range: before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 12:23:46.868896+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-106097.html