CVE-2026-93292
SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders
CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
| CWE | CWE-89 |
| Vendor | signoz |
| Product | signoz |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for signoz signoz
Be the first to know when new high vulnerabilities affecting signoz signoz are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
SigNoz / signoz
0.88.0 < 0.142.1
References
github.com: https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v github.com: https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d github.com: https://github.com/SigNoz/signoz/commit/8286e787b296b291a26a14d20407a335fcfbac25 github.com: https://github.com/SigNoz/signoz/releases/tag/v0.142.1 github.com: https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/modules/tracefunnel/clickhouse_queries.go#L498-L499 github.com: https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/query-service/app/http_handler.go#L4081-L4086 github.com: https://github.com/SigNoz/signoz vulncheck.com: https://www.vulncheck.com/advisories/signoz-0.88.0-before-0.142.1-sql-injection-in-trace-funnel-analytics-query-builders
Credits
4NK1T axel-corsiez morimori-dev newugly thaidn (Calif.io, in collaboration with Anthropic) hackchang Scott Moore - VulnCheck