#10 [highway] HIGH: SQL injection in delete_checkpoint and extend_claim

closed high Created 2025-11-25 20:28 · Updated 2025-11-25 22:46

Description

Edit
FIXED: delete_checkpoint (line 324) and extend_claim (line 494-505) now use psycopg.sql.Identifier for table names and parameterized intervals instead of f-string interpolation.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...