SQL Injection Affecting python-parsl package, versions <2026.01.05+ds-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-PYTHONPARSL-14907949
  • published9 Jan 2026
  • disclosed8 Jan 2026

Introduced: 8 Jan 2026

CVE-2026-21892  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade Debian:unstable python-parsl to version 2026.01.05+ds-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python-parsl package and not the python-parsl package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python % operator) with user-supplied input (workflow_id) directly from URL routes. This allows an unauthenticated attacker with access to the visualization dashboard to inject arbitrary SQL commands, potentially leading to data exfiltration or denial of service against the monitoring database. Version 2026.01.05 fixes the issue.

CVSS Base Scores

version 3.1