String Concatenation in pg8000 Queries
Building SQL queries with string concatenation instead of pg8000's parameter binding.
SQL injection vulnerability where SQL strings are built with variables using concatenation, formatting, or f-strings instead of pg8000 parameters, allowing attackers to alter queries, read sensitive data, or destroy tables.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
Building SQL queries with string concatenation instead of pg8000's parameter binding.
Sourcery automatically identifies sql injection from variable string concatenation in pg8000 sql statements and many other security issues in your codebase.