๐Ÿ” CVE Alert

CVE-2026-49490

HIGH 8.1

OpenCATS - SQL Injection in DataGrid Filter Handling for Tags Column

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
8th

OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manipulating filter requests to execute arbitrary SQL queries against the database.

CWE CWE-89
Vendor opencats
Product opencats
Published May 31, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for opencats opencats

Be the first to know when new high vulnerabilities affecting opencats opencats are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

OpenCATS / OpenCATS
0 โ‰ค 0.9.1a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/opencats/OpenCATS/security/advisories/GHSA-gmpc-j6h7-vw74 vulncheck.com: https://www.vulncheck.com/advisories/opencats-sql-injection-in-datagrid-filter-handling-for-tags-column