Impact
Marten, a .NET Transactional Document DB and Event Store on PostgreSQL, contains a severe SQL injection flaw that allows attackers to inject unescaped string literals into dynamically built SQL queries. The defect originates in the LINQ provider and tenant‑management paths, where runtime, potentially attacker‑controlled values are concatenated into single‑quoted SQL literals without escaping or parameterization. An attacker who can supply a crafted single quotation mark can escape the surrounding literal, thereby bypassing tenant authorization checks, extracting sensitive data, or modifying data if the application permits semicolon‑batched Npgsql statements.
Affected Systems
Applications using JasperFx.marten versions 7.0.0 up to but not including 9.13.0 are affected. The flaw is present in several LINQ components such as DictionaryItemMember, SelectParser, DatabaseScopedTenantPartitions, DeleteAllForTenant, and DictionaryContainsKeyFilter (the latter only when Newtonsoft.Json is used). Use of the EventLoader sink can also be impacted when per‑tenant partition pruning writes hard‑coded literals. All deployments running these versions on any PostgreSQL backend are vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity vulnerability. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the current environment, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted dictionary indexer key or similar user input passed through a LINQ filter, allowing an attacker to manipulate the generated SQL. If the application accepts semicolon‑separated statements via Npgsql, the attacker could further inject data‑modifying commands. Relying solely on the exposed information, an attacker could achieve substantial confidentiality and integrity impacts, potentially escalating to full remote code execution if dynamic SQL is executed with adequate privileges.
OpenCVE Enrichment
Github GHSA