Description
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a dictionary indexer key used by Where filters in src/Marten/Linq/Members/Dictionaries/DictionaryItemMember.cs. Additional affected sinks include SelectParser.cs, DatabaseScopedTenantPartitions.cs, and DeleteAllForTenant.cs reached through IEventStore.DeleteProjectionProgressAsync, while DictionaryContainsKeyFilter.cs (Newtonsoft serializer only; System.Text.Json is not affected) handles ContainsKey calls. Events/Daemon/Internals/EventLoader.cs contains a related per-tenant partition-pruning literal that the advisory identifies as a defense-in-depth sink. A crafted single quote can escape the generated literal, enabling filter or multi-tenant authorization bypass and blind data exfiltration, and deployments that permit semicolon-batched Npgsql statements may also allow data modification. This issue is fixed in version 9.13.0.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

Marten, a .NET Transactional Document DB and Event Store on PostgreSQL, contains a severe SQL injection flaw that allows attackers to inject unescaped string literals into dynamically built SQL queries. The defect originates in the LINQ provider and tenant‑management paths, where runtime, potentially attacker‑controlled values are concatenated into single‑quoted SQL literals without escaping or parameterization. An attacker who can supply a crafted single quotation mark can escape the surrounding literal, thereby bypassing tenant authorization checks, extracting sensitive data, or modifying data if the application permits semicolon‑batched Npgsql statements.

Affected Systems

Applications using JasperFx.marten versions 7.0.0 up to but not including 9.13.0 are affected. The flaw is present in several LINQ components such as DictionaryItemMember, SelectParser, DatabaseScopedTenantPartitions, DeleteAllForTenant, and DictionaryContainsKeyFilter (the latter only when Newtonsoft.Json is used). Use of the EventLoader sink can also be impacted when per‑tenant partition pruning writes hard‑coded literals. All deployments running these versions on any PostgreSQL backend are vulnerable.

Risk and Exploitability

The CVSS score of 9.1 indicates a high‑severity vulnerability. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the current environment, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted dictionary indexer key or similar user input passed through a LINQ filter, allowing an attacker to manipulate the generated SQL. If the application accepts semicolon‑separated statements via Npgsql, the attacker could further inject data‑modifying commands. Relying solely on the exposed information, an attacker could achieve substantial confidentiality and integrity impacts, potentially escalating to full remote code execution if dynamic SQL is executed with adequate privileges.

Generated by OpenCVE AI on September 17, 2026 at 21:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by installing Marten 9.13.0 or newer.
  • Disable or restrict semicolon batching in Npgsql connections to prevent multi‑statement injection.
  • Replace all dynamically constructed dictionary keys and LINQ filters with parameterized queries or validated literals.
  • If immediate upgrade is not feasible, restrict or disable tenant‑partitioning features that expose user‑controlled values to query construction.

Generated by OpenCVE AI on September 17, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rfx3-98h7-v3xp Marten's LINQ provider has SQL injection via unescaped string literals
History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Jasperfx
Jasperfx marten
Vendors & Products Jasperfx
Jasperfx marten

Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a dictionary indexer key used by Where filters in src/Marten/Linq/Members/Dictionaries/DictionaryItemMember.cs. Additional affected sinks include SelectParser.cs, DatabaseScopedTenantPartitions.cs, and DeleteAllForTenant.cs reached through IEventStore.DeleteProjectionProgressAsync, while DictionaryContainsKeyFilter.cs (Newtonsoft serializer only; System.Text.Json is not affected) handles ContainsKey calls. Events/Daemon/Internals/EventLoader.cs contains a related per-tenant partition-pruning literal that the advisory identifies as a defense-in-depth sink. A crafted single quote can escape the generated literal, enabling filter or multi-tenant authorization bypass and blind data exfiltration, and deployments that permit semicolon-batched Npgsql statements may also allow data modification. This issue is fixed in version 9.13.0.
Title Marten: SQL injection in Marten's LINQ provider via unescaped string literals
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-19T01:55:24.743Z

Reserved: 2026-08-17T20:49:21.599Z

Link: CVE-2026-75513

cve-icon Vulnrichment

Updated: 2026-09-19T01:55:18.915Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:13.440

Modified: 2026-09-19T02:16:54.140

Link: CVE-2026-75513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')