CVE-2026-40325: Cfml Unvalidated Table Name Setter

Unvalidated assignment to a variable representing a database table name. This allows potentially malicious strings to be used in dynamic SQL queries, leading to SQL Injection. Validate table names by restricting allowed characters, checking length, and ensuring the table exists.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Generic
greprules fetch cve-2026-40325-cfml-unvalidated-table-name-setter --engine opengrep

Description

Unvalidated assignment to a variable representing a database table name. This allows potentially malicious strings to be used in dynamic SQL queries, leading to SQL Injection. Validate table names by restricting allowed characters, checking length, and ensuring the table exists.