lowCVSS 3.1Vulnerability

GHSA-rxhg-vcww-2mpw

### Summary An authenticated user with read access to Activity could influence the `ORDER BY` clause of the activity list endpoints by supplying an arbitrary sort column: - `GET /api/v1/fleet/activities` (`ListActivities`) - `GET /api/v1/fleet/hosts/{id}/activities` (`ListHostPastActivities`) This originated from the deprecated cursor-pagination helper (`appendListOptionsWithCursorToSQL`), which interpolated the caller-supplied order key into SQL without an allowlist. The original report's `node_key` extraction scenario (`/api/v1/fleet/labels/{id}/hosts`) was remediated separately in #44385; these two activity endpoints were the residual call sites, neither of which joins the `hosts` table, so `node_key` was never reachable through them. ### Impact Read-only. Because the order key was interpolated, an authenticated user with Activity read could sort by columns not otherwise returned in these responses. The exposure was bounded to columns on `activity_past` (e.g. `details` on `/api/v1/fleet/activities`, which is not in that endpoint's SELECT; host-only activities are already excluded by `WHERE host_only = false`). There is no privilege escalation, write access, or reachability of `node_key` or other host-join columns through these endpoints. ### Remediation The deprecated helper was removed from the codebase. Both endpoints now pass the caller-supplied sort column through `SanitizeColumn`, which strips all characters except `[\w-.]` and backtick-quotes each identifier segment. This closes the injection vector: separators, whitespace, parentheses, and quotes cannot survive sanitization, so an expression-based `ORDER BY` oracle is not constructable. ### Affected versions `< fleet-v4.89.0`. Fixed in `fleet-v4.89.0`. ### Credit Thanks to @axel-corsiez for the report.

Properties

ghsa_id
GHSA-rxhg-vcww-2mpw
summary
Fleet: ORDER BY column injection on activity list endpoints
severity
low
cvss_score
3.1
cve_id
GHSA-rxhg-vcww-2mpw
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-08-20T18:44:36Z
source_url
https://github.com/advisories/GHSA-rxhg-vcww-2mpw
ghsa_updated
2026-08-20T18:44:39Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/fleetdm/fleet/v4

AFFECTS (1)

[Software]go/github.com/fleetdm/fleet/v4

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-rxhg-vcww-2mpw (CVSS 3.1) — Ninja Signal Threat Intelligence | Ninja Signal