Skip to content
dbt CoreGHSA-p72q-h37j-3hq7

dbt uses a SQLparse version with a high vulnerability

High7.5Published Apr 22, 2024 · updated Dec 5, 2024

### Summary Using a version of `sqlparse` that has a security vulnerability and no way to update in current version of dbt core. Snyk recommends using `sqlparse==0.5` but this causes a conflict with dbt. Snyk states the issues is a recursion error: `SNYK-PYTHON-SQLPARSE-6615674`. ### Details Dependency conflict error message: ```sh The conflict is caused by: The user requested sqlparse==0.5 dbt-core 1.7.10 depends on sqlparse<0.5 and >=0.2.3 ``` Resolution was to pin `sqlparse >=0.5.0, <0.6.0` in `dbt-core`, patched in 1.6.13 and 1.7.13. ### PoC From Snyk: ```python import sqlparse sqlparse.parse('[' * 10000 + ']' * 10000) ``` ### Impact Snyk classifies it as high 7.5/10. ### Patches The bug has been fixed in [dbt-core v1.6.13](https://github.com/dbt-labs/dbt-core/releases/tag/v1.6.13) and [dbt-core v1.7.13](https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.13). ### Mitigations Bump `dbt-core` 1.6 and 1.7 dependencies to 1.6.13 and 1.7.13 respectively

GitHub advisory

Affected versions

PackageAffectedFixed in
dbt-core
PyPI
>= 1.6.0, < 1.6.131.6.13
>= 1.7.0, < 1.7.131.7.13
Details and references

More dbt Core advisories

All dbt Core
Advisory
dbt has an implicit override for built-in materializations from installed packages
Low4.2Jul 17, 2024
dbt allows Binding to an Unrestricted IP Address via socketsocket
Medium5.3May 28, 2024
dbt-core's secret env vars written to package-lock.json in plaintext
Low3.2Dec 8, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.