{"id":"CVE-2026-28438","aliases":["GHSA-59g6-v3vg-f7wc","PYSEC-2026-2133"],"title":"CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements","summary":"CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements","severity":"high","vendor":"cocoindex","product":"cocoindex","ecosystem":"pip","affected":["cocoindex < 0.3.34"],"patched":["cocoindex 0.3.34"],"published":"2026-03-02","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-59g6-v3vg-f7wc","references":[{"url":"https://github.com/cocoindex-io/cocoindex/security/advisories/GHSA-59g6-v3vg-f7wc"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28438"},{"url":"https://github.com/cocoindex-io/cocoindex/commit/ba2fc4a89e22d35572c64bd2990737c7913b0729"},{"url":"https://github.com/cocoindex-io/cocoindex"}],"tags":["osv","pip"],"epss":0.00282,"epssPercentile":0.20928,"ingestedAt":"2026-07-13T18:57:53.122Z","slug":"CVE-2026-28438","body":"## Overview\n\n### Impact\nThe Doris target connector didn't verify the configured table name before creating some SQL statements (`ALTER TABLE`). So, in the application code, if the table name is provided by an untrusted upstream, it expose vulnerability to SQL injection when target schema change.\n\n### Patches\nYes, it's fixed in cocoindex 0.3.34: we start to validate table names passed to Doris target at entry point and error out immediately if it's not a valid identifier.\n\n### Workarounds\nUsers should make sure table names used to configure CocoIndex targets are valid, regardless of this fix. Which means\n\n- The table name comes from a trusted source (e.g. for most cases it's just a fixed string literal).\n- Even if it comes from an untrusted source (e.g. provided by end user), it should be validated before using it to configure the Doris target for CocoIndex.\n\n## Affected packages\n\n- `cocoindex < 0.3.34`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cocoindex 0.3.34`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}