CVE-2026-45288: Marten has an injection vulnerability in its full-text search regConfig parameter
(updated )
Marten’s full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45288 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →