highCVSS 8.5Vulnerability

GHSA-7xw9-549r-8jrc

### Details A number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. ### Patched versions: https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/

Properties

ghsa_id
GHSA-7xw9-549r-8jrc
severity
high
summary
DIRAC: SQL injection and lack of access control in PilotManager service
cvss_score
8.5
cve_id
GHSA-7xw9-549r-8jrc
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-07-13T18:38:13Z
source_url
https://github.com/advisories/GHSA-7xw9-549r-8jrc
ghsa_updated
2026-07-13T18:38:14Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]pip/DIRAC

AFFECTS (1)

[Software]pip/DIRAC

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
[Weakness]Improper Access Control

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-7xw9-549r-8jrc (CVSS 8.5) — Ninja Signal Threat Intelligence | Ninja Signal