๐Ÿ” CVE Alert

CVE-2026-18801

UNKNOWN 0.0

Stored Clickhouse SQL Injection Through Customer Usage Attribution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subjectKeys fields. When that customer is subsequently used in a meter or event query, OpenMeter inserts the stored value into a ClickHouse WITH map(...) expression using string concatenation. OpenMeter versions from v1.0.0-beta.218 through v1.0.0-beta.231 are affected.

CWE CWE-20
Vendor openmeter
Product openmeter
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for openmeter openmeter

Be the first to know when new unknown vulnerabilities affecting openmeter openmeter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openmeter / openmeter
v1.0.0-beta.218 โ‰ค v1.0.0-beta.231

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openmeterio/openmeter/security/advisories/GHSA-m2fw-9wxq-jgf5