Re: Possible command-injection or meta-command execution in `psql` input

From: Laurenz Albe <laurenz(dot)albe(at)cybertec(dot)at>
To: y(dot)saburov(at)gmail(dot)com, pgsql-docs(at)lists(dot)postgresql(dot)org
Subject: Re: Possible command-injection or meta-command execution in `psql` input
Date: 2026-09-28 12:51:30
Message-ID: fd897878c2324790143f5c4f4caa2b7388b88c68.camel@cybertec.at
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-docs

On Sat, 2026-09-26 at 08:27 +0000, PG Doc comments form wrote:
> AI generated ))

Then please validate the generated stuff rather than creating
extra work.

> The following SQL statement contains an unquoted regular-expression-like
> expression:
>
> db=# WITH products (id, name, price, action) AS
> (
> VALUES
>        (1, 'apple',  100, '...')
>      , (2, 'banana', 200, '...')
>      , (3, 'orange', 150, '...')
>      , (4, 'potato',  80, '...')
>      , (5, 'tomato', 120, '...')
> )
> SELECT
>        p.id
>      , p.name
>      , p.price
>      , p.action
>   FROM products AS p
>  WHERE regexp_like(p.action, ((?<!-)\d+))
> ;
>
> [the complaint is that you get a list of tables rather than a result]

There is no bug there. The statement is *not* a regular expression,
because the single quotes around the string literal are missing.
As a consequence, a metacommand (\d+) is executed. That "swallows"
the two closing parentheses, and psql prompts you to close the two
parentheses and end the statement. If you do that, you get the
syntax error you deserve.

In short: garbage in, garbage out. No bug.

Yours,
Laurenz Albe

In response to

Browse pgsql-docs by date

  From Date Subject
Next Message Matemática A3K 2026-09-28 12:56:46 Re: Possible command-injection or meta-command execution in `psql` input
Previous Message Laurenz Albe 2026-09-27 12:08:17 Re: log_line_prefix and JSON log format