๐Ÿ” CVE Alert

CVE-2026-59894

UNKNOWN 0.0

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQL to terminate the generated string and inject Python or PHP code when a downstream consumer executes or imports the generated source. This issue is fixed in version 0.6.0.

CWE CWE-94
Vendor andialbrecht
Product sqlparse
Published Aug 17, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for andialbrecht sqlparse

Be the first to know when new unknown vulnerabilities affecting andialbrecht sqlparse are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

andialbrecht / sqlparse
< 0.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x