diff --git a/advisories/github-reviewed/2025/12/GHSA-qhqw-rrw9-25rm/GHSA-qhqw-rrw9-25rm.json b/advisories/github-reviewed/2025/12/GHSA-qhqw-rrw9-25rm/GHSA-qhqw-rrw9-25rm.json index 814fe8639a753..f8981cb7985b5 100644 --- a/advisories/github-reviewed/2025/12/GHSA-qhqw-rrw9-25rm/GHSA-qhqw-rrw9-25rm.json +++ b/advisories/github-reviewed/2025/12/GHSA-qhqw-rrw9-25rm/GHSA-qhqw-rrw9-25rm.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-qhqw-rrw9-25rm", - "modified": "2026-03-10T17:50:57Z", + "modified": "2026-03-10T17:50:58Z", "published": "2025-12-02T21:31:30Z", "aliases": [ "CVE-2025-65896" ], "summary": "asyncmy is vulnerable to SQL injection via crafted dict keys", - "details": "SQL injection vulnerability in long2ice asyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.", + "details": "SQL injection vulnerability in long2ice asyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.\n\n\"The official maintainers of long2ice/asyncmy patched the improper dictionary key escaping flaw in Pull Request #141. This fix was tagged and released starting in version 0.2.11. The current NVD data confirms that only versions up to and including 0.2.10 are vulnerable. Version 0.2.11 should be excluded from the affected range.\"", "severity": [ { "type": "CVSS_V3", @@ -28,11 +28,14 @@ "introduced": "0" }, { - "last_affected": "0.2.11" + "fixed": "0.2.11" } ] } - ] + ], + "database_specific": { + "last_known_affected_version_range": "<= 0.2.10" + } } ], "references": [