CyberRota Analysis
AI-GeneratedPyAthena versions prior to 3.35.4 are vulnerable to a SQL injection flaw that allows unauthenticated attackers to execute arbitrary SQL commands due to improper quote-escaping in the DefaultParameterFormatter.format() function. This vulnerability can lead to severe consequences, including data exfiltration and execution of destructive SQL statements. Organizations using PyAthena should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.