13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/lf-edge/ekuiper is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.8
CVE-2024-43406
LF Edge eKuiper has a SQL Injection in sqlKvStore
UNKNOWN
GHSA-rj4j-2jph-gg43
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper
UNKNOWN
GHSA-gj54-gwj9-x2c6
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper
UNKNOWN
GHSA-fv2p-qj5p-wqq4
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper
UNKNOWN
CVE-2025-54379
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper
UNKNOWN
CVE-2024-52290
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper
UNKNOWN
CVE-2024-52812
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper
UNKNOWN
CVE-2024-43406
LF Edge eKuiper has a SQL Injection in sqlKvStore in github.com/lf-edge/ekuiper
UNKNOWN
CVE-2025-54379
eKuiper API endpoints handling SQL queries with user-controlled table names.
UNKNOWN
GO-2025-3800
eKuiper /config/uploads API arbitrary file writing may lead to RCE
HIGH 8.5
GO-2025-3799
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement
MEDIUM 6.3
CVE-2024-52290
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality
MEDIUM 5.4
CVE-2024-52812
LF Edge eKuiper allows Stored XSS in Rules Functionality
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes