All findings

CVE-2026-8462 medium

Claude discovers OpenMeter SQL injection triaged by Anvil Secure

GitHub's reviewed advisory for CVE-2026-8462 says Claude, Anthropic's AI assistant, discovered an OpenMeter SQL injection that Anvil Secure triaged with Anthropic Research.

Bug class
Authenticated SQL injection in meter creation
Affected codebase
OpenMeter
Credited system
Claude / Anthropic Research
Disclosed
June 4, 2026
Attribution
Direct source attribution
Severity
medium
Source status: The GitHub reviewed advisory directly states that Claude discovered the vulnerability and that Shoshana Makinen at Anvil Secure triaged it in collaboration with Anthropic Research. The advisory is patched in OpenMeter 1.0.0-beta.228.

Summary

CVE-2026-8462 is an authenticated SQL injection in OpenMeter’s meter creation path. User-controlled valueProperty or groupBy input could reach a ClickHouse query through string interpolation and escape JSONPath validation, allowing cross-tenant data access in affected deployments.

Attribution

This is one of the clearest single-vulnerability Claude records: the GitHub reviewed advisory states that Claude discovered the issue and that Anvil Secure triaged it with Anthropic Research. The public advisory also includes affected versions, patch version, proof-of-concept detail, and impact analysis.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.