CVE-2026-33158: Craftcms Query Configure Injection

Passing unsanitized user-supplied criteria to `Craft::configure()` on a query object can allow SQL injection if the keys include query properties like 'where', 'select', 'join', etc. Always remove unsupported or dangerous keys from user-supplied criteria before passing them to configuration functions.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-33158-craftcms-query-configure-injection --engine opengrep

Description

Passing unsanitized user-supplied criteria to `Craft::configure()` on a query object can allow SQL injection if the keys include query properties like 'where', 'select', 'join', etc. Always remove unsupported or dangerous keys from user-supplied criteria before passing them to configuration functions.