๐Ÿ” CVE Alert

CVE-2026-40887

CRITICAL 9.1

@vendure/core has a SQL Injection vulnerability

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database. This affects all supported database backends (PostgreSQL, MySQL/MariaDB, SQLite). The Admin API is also affected, though exploitation there requires authentication. Versions 2.3.4, 3.5.7, and 3.6.2 contain a patch. For those who are unable to upgrade immediately, Vendure has made a hotfix available that uses `RequestContextService.getLanguageCode` to validate the `languageCode` input at the boundary. This blocks injection payloads before they can reach any query. The hotfix replaces the existing `getLanguageCode` method in `packages/core/src/service/helpers/request-context/request-context.service.ts`. Invalid values are silently dropped and the channel's default language is used instead. The patched versions additionally convert the vulnerable SQL interpolation to a parameterized query as defense in depth.

CWE CWE-89
Vendor vendurehq
Product vendure
Published Apr 21, 2026
Stay Ahead of the Next One

Get instant alerts for vendurehq vendure

Be the first to know when new critical vulnerabilities affecting vendurehq vendure are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High

Affected Versions

vendurehq / vendure
>= 3.0.0, < 3.5.7 >= 3.6.0, < 3.6.2 >= 1.7.4, < 2.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vendurehq/vendure/security/advisories/GHSA-9pp3-53p2-ww9v