Impact
The vulnerability is a SQL injection flaw in the ClickHouse-backed meter definitions of OpenMeter. An attacker can supply crafted JSONPath values to the meters API, allowing remote execution of arbitrary SQL statements against the ClickHouse database. This can lead to unauthorized reading or modification of metering event data and may cause denial of service by overloading or corrupting the database. The weakness is a classic injection flaw identified as CWE‑89.
Affected Systems
The issue affects all installations of OpenMeter (openmeter:openmeter) running any version prior to 1.0.0‑beta.228. No platform‑specific limitations were noted, so the vulnerability is present on every supported operating system.
Risk and Exploitability
The vulnerability has a CVSS score of 8.9, indicating high severity. The EPSS score is below 1 %, implying low expected exploitation frequency, and it is not listed in the CISA KEV catalog. Attackers would need only network access to the exposed meters API and no authentication, making the route relatively straightforward but still opportunistic. Given the high severity and the fact that the attacker can affect data integrity, confidentiality, and availability, the overall risk warrants prompt attention.
OpenCVE Enrichment
Github GHSA