CVE-2026-51936 SQLCipher sqlcipher_export SQL 注入漏洞
影响攻击者可绕过防御限制篡改数据库结构,导致数据库损坏
SQLCipher 4.15.0 之前版本的 sqlcipher_export 便捷函数在处理源数据库名参数时存在缺陷。该函数为进行动态 schema 操作会临时清除防御限制,而源数据库名未严格校验,导致调用者可注入恶意语句。攻击者可借此直接修改 sqlite_schema 表并造成数据库损坏。
影响范围
Zetetic SQLCipher 4.15.0 之前的版本。
漏洞详情
漏洞类型为 SQL 注入。成因是 sqlcipher_export 在执行动态 schema 操作时会临时关闭防御模式,但对源数据库名参数校验不严。调用者传入特制源名即可执行本应被防御模式拦截的语句,从而直接修改 sqlite_schema 表。
利用条件与风险
利用前提是攻击者能控制 sqlcipher_export 的源数据库名参数。实战中可导致数据库结构被篡改或数据库损坏,具体 CVSS 评分暂无公开信息。
修复建议
升级至 SQLCipher 4.15.0 或更高版本,该版本已严格校验源数据库名并阻止绕过。临时缓解措施暂无公开信息。
Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.