CVE-2026-51936: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Zetetic SQLCipher
Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.
AI Analysis
Technical Summary
Zetetic SQLCipher before version 4.15.0 contains an SQL injection vulnerability in the sqlcipher_export function. This function temporarily disables defensive restrictions to perform dynamic schema changes when copying database contents. Due to insufficient validation of the source database name parameter, an attacker can supply crafted input that executes SQL statements normally blocked by defensive mode. This can lead to direct modifications of the sqlite_schema table and database corruption. The vulnerability is addressed in version 4.15.0 by enforcing strict validation of the source database name to prevent bypassing defensive restrictions.
Potential Impact
An attacker with local access and the ability to call sqlcipher_export can exploit this vulnerability to execute unauthorized SQL commands that modify the database schema, potentially corrupting the database. The impact is limited by the requirement for local access and the low CVSS score indicates limited exploitability and impact.
Mitigation Recommendations
Upgrade to SQLCipher version 4.15.0 or later, which includes a fix that strictly validates the source database name parameter to prevent SQL injection. No other mitigation is indicated or required.
CVE-2026-51936: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Zetetic SQLCipher
Description
Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.
CVSS v4.0
Score 2.1low
Affected software
Zetetic
SQLCipher
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Zetetic SQLCipher before version 4.15.0 contains an SQL injection vulnerability in the sqlcipher_export function. This function temporarily disables defensive restrictions to perform dynamic schema changes when copying database contents. Due to insufficient validation of the source database name parameter, an attacker can supply crafted input that executes SQL statements normally blocked by defensive mode. This can lead to direct modifications of the sqlite_schema table and database corruption. The vulnerability is addressed in version 4.15.0 by enforcing strict validation of the source database name to prevent bypassing defensive restrictions.
Potential Impact
An attacker with local access and the ability to call sqlcipher_export can exploit this vulnerability to execute unauthorized SQL commands that modify the database schema, potentially corrupting the database. The impact is limited by the requirement for local access and the low CVSS score indicates limited exploitability and impact.
Mitigation Recommendations
Upgrade to SQLCipher version 4.15.0 or later, which includes a fix that strictly validates the source database name parameter to prevent SQL injection. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-08T01:02:33.711Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abc5d2e680226ef6899b9e2
Added to database: 09/30/2026, 00:51:58 UTC
Last enriched: 09/30/2026, 01:21:53 UTC
Last updated: 09/30/2026, 03:03:19 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.