Impact
The vulnerability lies in the trace-funnel analytics queries, where the service_name and span_name values are interpolated directly into ClickHouse string literals without any escaping. Because these values are not validated, an attacker who has authenticated access to the system can supply crafted input that modifies the structure of the SQL statement. This enables the attacker to execute arbitrary queries against the ClickHouse database, potentially exposing sensitive data returned in the HTTP response. The attack relies on the fact that the query builder does not use parameterized queries or input validation, making the software susceptible to classic SQL injection.
Affected Systems
SigNoz Signoz versions 0.88.0 through 0.142.0 (inclusive) are affected. Any deployment that exposes the trace funnel analytics endpoints and allows users to create or modify funnel step definitions within this version range is vulnerable.
Risk and Exploitability
The CVSS score of 8.4 marks this issue as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the near term, but the problem remains significant because it requires authentication and grants the ability to execute arbitrary queries. The vulnerability is not in the CISA KEV catalog, yet the potential for data exfiltration and database corruption warrants prompt remediation.
OpenCVE Enrichment