Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1xB6RM-000000030SR-3l21 for pgsql-docs@arkaria.postgresql.org; Mon, 28 Sep 2026 08:10:25 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1xB6RM-00000008MbK-0l81 for pgsql-docs@arkaria.postgresql.org; Mon, 28 Sep 2026 08:10:24 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1xANlU-00000003qkN-01ha for pgsql-docs@lists.postgresql.org; Sat, 26 Sep 2026 08:28:12 +0000 Received: from mahout.postgresql.org ([2001:4800:3e1:1::227]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1xANlP-00000001N2N-03VI for pgsql-docs@lists.postgresql.org; Sat, 26 Sep 2026 08:28:11 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=postgresql.org; s=20171124; h=Message-ID:Date:Reply-To:Cc:From:To:Subject: Content-Transfer-Encoding:MIME-Version:Content-Type:Sender:Content-ID: Content-Description:In-Reply-To:References; bh=e4sdjs88RBGTXpv0Ahpf4sR/Kk3YC2NPpRSs3lDJOfg=; b=Cl22axcdXdPQDhny/MevUiIs/M PMGHfmqLipWVsI+We4uQ/8sDnAD9n4gUKFSu9aKjjv1EvHaycA1qvRIdFbQbW4Awf6QeGyW9vR4Xt 1onwItz4WzkSmyskjfWi4ZnNq8itsgyfLan9m1ljmMHURkIQbpCI2pH6Ngcf9RRN4yM/PYnqT9yem KcLUX8NfycF8fyliM1aj7ocP9Cr9rMqcAGCzWJFvgYOBweGZBVGRex/iAJR9JawJyqPx2ZVKBxyHw bYoJLvkqoAGU/26rpFHIrHdp8+OhMqxklWDpUrG72HHio+YVxJ6UgCRyDeJoesIeYMOwd4Im0IFCg 8QFcnoNQ==; Received: from wrigleys.postgresql.org ([2a02:16a8:dc51::60]) by mahout.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1xANlN-003w8i-1t for pgsql-docs@lists.postgresql.org; Sat, 26 Sep 2026 08:28:05 +0000 Received: from localhost ([127.0.0.1] helo=wrigleys.postgresql.org) by wrigleys.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1xANlL-0000000BOnF-0sxk for pgsql-docs@lists.postgresql.org; Sat, 26 Sep 2026 08:28:03 +0000 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Subject: Possible command-injection or meta-command execution in `psql` input To: pgsql-docs@lists.postgresql.org From: PG Doc comments form Cc: y.saburov@gmail.com Reply-To: y.saburov@gmail.com, pgsql-docs@lists.postgresql.org Date: Sat, 26 Sep 2026 08:27:10 +0000 Message-ID: <179041123000.1026192.10336293169834979882@wrigleys.postgresql.org> X-Auto-Response-Suppress: All Auto-Submitted: auto-generated List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk The following documentation comment has been logged on the website: Page: https://www.postgresql.org/docs/18/index.html Description: AI generated )) ## Summary The following SQL statement contains an unquoted regular-expression-like expression: ```sql db=3D# WITH products (id, name, price, action) AS ( VALUES (1, 'apple', 100, '...') , (2, 'banana', 200, '...') , (3, 'orange', 150, '...') , (4, 'potato', 80, '...') , (5, 'tomato', 120, '...') ) SELECT p.id , p.name , p.price , p.action FROM products AS p WHERE regexp_like(p.action, ((?