VYPR

TDengine DAQ storage connector

by TDengine

CVEs (1)

  • CVE-2026-47720Jun 8, 2026
    risk 0.00cvss epss

    ## Summary The TDengine DAQ storage connector's `escapeTdString` at `server/runtime/storage/tdengine/index.js:10` doubles single quotes but does not escape backslashes. TDengine's SQL parser treats `\'` as a literal single quote inside a string, so a tag id of the form `x\' OR…