LevelBlue SpiderLabs: SQL Injection in Orkes Conductor: CVE-2025-66387
ID: 1f4959dd-e7da-5aaf-93ef-5acd9933e36e
STIX ID: report--1f4959dd-e7da-5aaf-93ef-5acd9933e36e
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
LevelBlue SpiderLabs disclosed a time-based blind SQL injection vulnerability (CVE-2025-66387) in Orkes Conductor v5.2.4 affecting the /api/workflow/search endpoint: authenticated attackers can inject crafted expressions into the `sort` parameter (e.g., PG_SLEEP-based payloads) to enumerate and exfiltrate PostgreSQL database names and contents; Orkes has remediated the issue and users are advised to upgrade and implement input validation and prepared statements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
