github.com/lf-edge/ekuiper
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/lf-edge/ekuiperpage 1 of 1
- CVE-2024-43406HIGHCVSS 8.8EG 8.8fixed in 1.14.22024-08-20
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sq…
- CVE-2024-52290MEDIUMCVSS 6.3EG 6.32025-05-14
LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into …
- CVE-2024-52812MEDIUMCVSS 5.4EG 5.42025-03-10
LF Edge eKuiper is an internet-of-things data analytics and stream processing engine. Prior to version 2.0.8, auser with rights to modify the service (e.g. kuiperUser role) can inject a cross-site scripting payload into the rule `id` param…
- CVE-2025-24978LOWCVSS 3.7EG 3.72026-09-09
LF Edge eKuiper: Self-XSS in External Service Creation ### Summary A Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which …
- CVE-2025-24979MEDIUMCVSS 5.5EG 5.52026-09-09
LF Edge eKuiper: SSRF in External Service ### Summary Server-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make reque…
- CVE-2025-54379CRITICALCVSS 9.8EG 9.82025-07-24
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the…
- CVE-2025-58363MEDIUMCVSS 5.5EG 5.52026-09-09
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint ### Summary A path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers wit…
Check whether github.com/lf-edge/ekuiper is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/lf-edge/ekuiper CVEs against the assets you own.
Book a Demo →