---
id: GO-2026-6269
aliases:
  - GHSA-rxhg-vcww-2mpw
title: >-
  Fleet: ORDER BY column injection on activity list endpoints in
  github.com/fleetdm/fleet
summary: >-
  Fleet: ORDER BY column injection on activity list endpoints in
  github.com/fleetdm/fleet
severity: none
vendor: fleetdm
product: github.com/fleetdm/fleet/v4
ecosystem: go
affected:
  - github.com/fleetdm/fleet/v4 < 4.89.0
patched:
  - github.com/fleetdm/fleet/v4 4.89.0
published: '2026-08-25'
updated: '2026-08-26'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-6269'
references:
  - url: 'https://github.com/fleetdm/fleet/security/advisories/GHSA-rxhg-vcww-2mpw'
  - url: 'https://github.com/fleetdm/fleet/releases/tag/fleet-v4.89.0'
tags:
  - osv
  - go
ingestedAt: '2026-08-26T19:27:03.243Z'
---

## Overview

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

## Affected packages

- `github.com/fleetdm/fleet/v4 < 4.89.0`

## Remediation

Upgrade to a patched release:

- `github.com/fleetdm/fleet/v4 4.89.0`
