Summary
CVE-2026-8462 is an authenticated SQL injection in OpenMeter’s meter creation
path. User-controlled valueProperty or groupBy input could reach a
ClickHouse query through string interpolation and escape JSONPath validation,
allowing cross-tenant data access in affected deployments.
Attribution
This is one of the clearest single-vulnerability Claude records: the GitHub reviewed advisory states that Claude discovered the issue and that Anvil Secure triaged it with Anthropic Research. The public advisory also includes affected versions, patch version, proof-of-concept detail, and impact analysis.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.