VYPR

Ecto

by Ecto

Source repositories

CVEs (2)

  • CVE-2017-20166CriJan 10, 2023
    risk 0.57cvss 9.8epss 0.01

    Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.

  • CVE-2026-66838HigAug 7, 2026
    risk 0.46cvss 8.2epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and…