Skip to content

[Aikido] Fix SQL injection bypass in asyncpg.executemany parameter extraction - #744

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137918973-xvjr
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137918973-xvjr

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a SQL injection vulnerability bypass in the asyncpg.executemany method where the security scanner was incorrectly extracting the query parameter instead of the command parameter, allowing malicious SQL to evade detection. A dedicated wrapper function _executemany was implemented to correctly identify and scan the command parameter for SQL injection attacks. The fix ensures proper vulnerability detection for batch query execution in asyncpg connections and includes comprehensive test coverage in aikido_zen/sinks/asyncpg.py and aikido_zen/sinks/tests/asyncpg_test.py.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811708154
HIGH
This is a protection-mechanism bypass in code within the audit scope. For an instrumented request handled in blocking mode, an application that incorporates request-controlled data into an asyncpg command can call connection.executemany(command=statement, args=rows). _execute requests query, so get_argument returns None; context_contains_sql_injection skips that value; and the wrapper proceeds to call the original method with the untouched arguments. No later check in this sink scans command. Consequently, SQL injection that this firewall is intended to detect and block can execute with the application's database role and evade the associated attack telemetry. The impact is conditional on an application endpoint constructing the command from attacker-influenced data, but that is the trust boundary the sink is intended to protect.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant