SQL Injection Affecting marten package, versions [7.0.0, 9.13.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.47% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DOTNET-MARTEN-20074855
  • published24 Sept 2026
  • disclosed17 Sept 2026
  • creditsvenclaesson

Introduced: 17 Sep 2026

NewCVE-2026-75513  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade Marten to version 9.13.0 or higher.

Overview

Affected versions of this package are vulnerable to SQL Injection via unescaped string literals in DictionaryItemMember, DictionaryContainsKeyFilter, SelectParser, DeleteAllForTenant, DatabaseScopedTenantPartitions, and EventLoader. An attacker can inject arbitrary SQL, bypass tenant or row filters, and exfiltrate data by supplying a value containing a single quote in a dictionary indexer key, ContainsKey argument, projected constant, or tenant id used in partitioning or teardown SQL.

Workarounds

  • Do not pass untrusted input as a dictionary indexer key, ContainsKey argument, or Select constant.
  • Do not pass untrusted input as a tenant id into projection teardown or tenant partition provisioning.
  • Disable multi-statement command batching to limit the blast radius if SQL injection is triggered.

CVSS Base Scores

version 4.0
version 3.1