piccolo@1.0a1 vulnerabilities

A fast, user friendly ORM and query builder which supports asyncio.

  • latest version

    1.22.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the piccolo package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    piccolo is an A fast, user friendly ORM and query builder which supports asyncio.

    Affected versions of this package are vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the handling of named transaction savepoints in all database implementations, when a provided input is passed directly to connection.execute(...) via f-strings.

    How to fix Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')?

    Upgrade piccolo to version 1.1.1 or higher.

    [,1.1.1)