---
id: CVE-2026-57230
title: OpenReplay is a self-hosted session replay suite
summary: >-
  OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session
  search and analytics API in enterprise editions with multi-tenancy enabled
  built ClickHouse queries by inserting user input into the query string,
  including t…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L'
cwe:
  - CWE-89
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57230'
references:
  - url: >-
      https://github.com/openreplay/openreplay/commit/ae8de6893250dd41175c6b2d312545c515fa5a16
    label: security-advisories@github.com
  - url: 'https://github.com/openreplay/openreplay/pull/4715'
    label: security-advisories@github.com
  - url: 'https://github.com/openreplay/openreplay/releases/tag/v1.27.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/openreplay/openreplay/security/advisories/GHSA-vxf8-j7jx-p65x
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00339
epssPercentile: 0.2732
ingestedAt: '2026-07-11T20:15:27.364Z'
---

## Overview

OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy enabled built ClickHouse queries by inserting user input into the query string, including two positions that took input without escaping, allowing an authenticated member to read any ClickHouse table through blind boolean and time-based exfiltration and to break the project's session search for all viewers until the stored key is removed. This issue is fixed in version 1.27.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
