9 min read

pREST v2.4.1 and v2.4.2: You Cannot Blacklist Your Way Out of SQL Injection

pREST v2.4.1 closes an 8.6 SQL injection in _QUERIES templates and an /_mcp catalog-exposure bypass — then its SQL-keyword blacklist silently blanked 17.5% of one production catalog. v2.4.2 replaces screening with real parameter binding, adds script path-traversal containment, and enforces RFC 7518 minimum JWT key sizes.