SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v
https://github.com/SigNoz/signoz/releases/tag/v0.142.1
https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d
https://github.com/SigNoz/signoz/commit/8286e787b296b291a26a14d20407a335fcfbac25
https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/query-service/app/http_handler.go#L4081-L4086
Published: 2026-09-17
Updated: 2026-09-17
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N
Severity: High
Base Score: 8.5
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Severity: High
Base Score: 8.4
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Severity: High