>_
.issue.db
/highway-workflow-engine
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
#375
HIGH: SQL injection pattern in platform.py tenant deletion
closed
high
Created 2025-12-11 21:54
·
Updated 2025-12-11 22:05
Description
Edit
platform.py:1083-1121 uses f-strings for table names in DELETE queries. Should use psycopg.sql.Identifier() for safe identifier quoting to prevent SQL injection.
Similar Issues
Loading similar issues...
Comments
Loading comments...
Add Comment
Context
Loading context...
Audit History
View All
Loading audit history...
Quick Actions
Reopen
Edit
Status
Open
In Progress
Closed
Won't Do
Priority
Low
Medium
High
Critical
Danger Zone
Delete Issue