highCVSS 7.2Vulnerability

GHSA-h8cj-hpmg-636v

### Summary A SQL injection vulnerability exists in `FilterDataServiceCE.java` where the `dropTable` method constructs a SQL `DROP TABLE` statement using string concatenation with the table name. If the table name is derived from user input, this allows for arbitrary SQL command execution. ### Details The vulnerability is located in `app/server/appsmith-interfaces/src/main/java/com/appsmith/external/services/ce/FilterDataServiceCE.java`. Line 627 in `dropTable` method: ```java public void dropTable(String tableName) { String dropTableQuery = "DROP TABLE " + tableName + ";"; executeDbQuery(dropTableQuery); } ``` The `tableName` argument is concatenated directly into the SQL string without validation or escaping. ### PoC If `dropTable` is exposed to user input (e.g., via a utility API that accepts a table name to clean up), an attacker could provide a value like: `valid_table; DROP TABLE users; --` The resulting query would be: `DROP TABLE valid_table; DROP TABLE users; --;` This would delete the intended table and then delete the `users` table (or execute any other injected SQL). ### Impact * **Type:** SQL Injection * **Impact:** Data Loss (Drop Table), potentially Data Exfiltration or Modification depending on database permissions. * **Who is impacted:** Appsmith server instances.

Properties

ghsa_id
GHSA-h8cj-hpmg-636v
severity
high
summary
appsmith has SQL Injection in FilterDataService via Unsafe DROP TABLE Execution
cvss_score
7.2
cve_id
GHSA-h8cj-hpmg-636v
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-04-29T20:59:45Z
source_url
https://github.com/advisories/GHSA-h8cj-hpmg-636v
ghsa_updated
2026-04-29T20:59:45Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]maven/com.appsmith:interfaces

AFFECTS (1)

[Software]maven/com.appsmith:interfaces

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph