Impact
Authenticated users with a Viewer role or higher can exploit a flaw in the v5 query_range API of SigNoz by embedding backticks and quotes in telemetry field-key names. The application fails to properly escape these values, allowing attackers to break out of identifiers and string literals. The resulting injection enables arbitrary ClickHouse SQL execution, which can read system tables and exfiltrate sensitive data. This vulnerability is a classic example of SQL injection, identified by CWE-89.
Affected Systems
All SigNoz installations running versions 0.87.0 through 0.141.x are affected. The flaw exists in the codebase prior to the release of version 0.142.0, which introduced proper escaping for field-key names in the query builder.
Risk and Exploitability
With a CVSS score of 8.4, this vulnerability is considered high severity. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Nevertheless, authenticated attackers who can assign field-key names can execute malicious queries. The attack vector requires user credentials with at least Viewer privileges and can be carried out by submitting specially crafted field-key names to the query_range endpoint. The impact includes unauthorized data access and potential data exfiltration from the ClickHouse backend.
OpenCVE Enrichment