logo

LevelBlue SpiderLabs: SQL Injection in Orkes Conductor: CVE-2025-66387

ID: ec772a46-7ed4-5ff0-81cc-c3980bd004d7

STIX ID: report--ec772a46-7ed4-5ff0-81cc-c3980bd004d7

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
65/100

Date Published: 2025-12-18

Date Updated: 2026-04-28

Author: Tim Stamopoulos

...
...

LevelBlue SpiderLabs disclosed an authenticated time-based blind SQL injection in Orkes Conductor v5.2.4 (Platform v1.19.12) where the `sort` parameter of /api/workflow/search is unsafely embedded into PostgreSQL queries; proof-of-concept payloads caused measurable delays (e.g., PG_SLEEP(5)) enabling enumeration and exfiltration of database names, tables, and columns. Orkes has issued a fix and users are advised to update, validate/escape inputs, and use prepared statements. (CVE-2025-66387)

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.