logo

LevelBlue SpiderLabs: SQL Injection in Orkes Conductor: CVE-2025-66387

ID: 1f4959dd-e7da-5aaf-93ef-5acd9933e36e

STIX ID: report--1f4959dd-e7da-5aaf-93ef-5acd9933e36e

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
70/100

Date Published: 2025-12-18

Date Updated: 2026-04-28

Author: Tim Stamopoulos

...
...

LevelBlue SpiderLabs disclosed a time-based blind SQL injection vulnerability (CVE-2025-66387) in Orkes Conductor v5.2.4 affecting the /api/workflow/search endpoint: authenticated attackers can inject crafted expressions into the `sort` parameter (e.g., PG_SLEEP-based payloads) to enumerate and exfiltrate PostgreSQL database names and contents; Orkes has remediated the issue and users are advised to upgrade and implement input validation and prepared statements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.