Re: Possible command-injection or meta-command execution in `psql` input - Mailing list pgsql-docs

From Laurenz Albe
Subject Re: Possible command-injection or meta-command execution in `psql` input
Date
Msg-id fd897878c2324790143f5c4f4caa2b7388b88c68.camel@cybertec.at
Whole thread
In response to Possible command-injection or meta-command execution in `psql` input  (PG Doc comments form <noreply@postgresql.org>)
List pgsql-docs
On Sat, 2026-09-26 at 08:27 +0000, PG Doc comments form wrote:
> AI generated ))

Then please validate the generated stuff rather than creating
extra work.

> The following SQL statement contains an unquoted regular-expression-like
> expression:
>
> db=# WITH products (id, name, price, action) AS
> (
> VALUES
>        (1, 'apple',  100, '...')
>      , (2, 'banana', 200, '...')
>      , (3, 'orange', 150, '...')
>      , (4, 'potato',  80, '...')
>      , (5, 'tomato', 120, '...')
> )
> SELECT
>        p.id
>      , p.name
>      , p.price
>      , p.action
>   FROM products AS p
>  WHERE regexp_like(p.action, ((?<!-)\d+))
> ;
>
> [the complaint is that you get a list of tables rather than a result]

There is no bug there.  The statement is *not* a regular expression,
because the single quotes around the string literal are missing.
As a consequence, a metacommand (\d+) is executed.  That "swallows"
the two closing parentheses, and psql prompts you to close the two
parentheses and end the statement.  If you do that, you get the
syntax error you deserve.

In short: garbage in, garbage out.  No bug.

Yours,
Laurenz Albe



pgsql-docs by date:

Previous
From: Laurenz Albe
Date:
Subject: Re: log_line_prefix and JSON log format
Next
From: Matemática A3K
Date:
Subject: Re: Possible command-injection or meta-command execution in `psql` input