AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Pg-Meta Schemas.Update/Remove DO Blocks Fail When Identifiers Contain '$$'

The pg-meta schemas update and remove methods construct DO blocks with fixed $$ dollar-quote delimiters. If any interpolated identifier (schema name, new name, or owner) contains the byte sequence '$$', the PostgreSQL parser prematurely closes the dollar quote, leading to a syntax error and potential SQL injection if the truncation leaves executable statements.

criticalConfidence 95%PostgreSQL

Origin Analysis

The code in packages/pg-meta/src/pg-meta-schemas.ts uses literal '$$' as the dollar-quote delimiter for DO blocks without checking whether any user-controlled value interpolated into the block body contains that exact sequence. PostgreSQL treats the first '$$' inside the body as the closing delimiter, truncating the block and causing parsing errors or unintended statement execution.
1. Create a schema with a name containing '$$', e.g. CREATE SCHEMA "weird$$name"; 2. Call pgMeta.schemas.update({ name: 'weird$$name' }, { name: 'weird$$name' }) or pgMeta.schemas.remove('weird$$name'). 3. Observe that the generated DO block contains '$$' inside the quoted name, causing PostgreSQL to close the block early and throw a syntax error at or near the remaining body content.

Fixing Code Block

Edge Case Audit

The while loop could theoretically run long if an attacker supplies values containing many underscore-prefixed dollar-quote sequences, though practical limits are high; consider capping iterations to avoid pathological cases. This fix does not affect concurrency or threading as the SQL is dynamically generated per call. When rolling back, revert to the original fixed '$$' delimiter only if no values can contain '$$', or keep the helper. Ensure the database user has appropriate privileges for schema alteration/removal, as before.

Ecosystem Topology