VYPR

Pyathena

by Pyathena Dev

Source repositories

CVEs (1)

  • CVE-2026-65321CriAug 2, 2026
    risk 0.57cvss 9.8epss 0.01

    PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that…