CVE-2026-40887 | vendurehq vendure up to 2.3.3/3.5.6/3.6.1 Vendure Shop API sql injection
A vulnerability described as critical has been identified in vendurehq vendure up to 2.3.3/3.5.6/3.6.1. This affects an unknown part of the component Vendure Shop API. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-40887. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.