Python

Python web applications query through Django's ORM or SQLAlchemy, both of which bind parameters on their normal query paths. Injection shows up at the deliberate escape hatches and at the places where a query is assembled from strings rather than expressions.

The ORMs here#

  • Django ORM: raw() and cursor.execute(), extra() select and where fragments, and lookup construction in filter().
  • SQLAlchemy: text() clauses and raw execute() built by string formatting rather than bound parameters.

The shared pattern#

Both ORMs are safe when the query is expressed through their API with bound parameters, and vulnerable when a developer formats a string. Django's raw()/extra() and SQLAlchemy's text() are the explicit raw surfaces; the subtler case is building a filter, a lookup, or an ORDER BY from input, where the structure (not just a value) comes from the caller. Identifiers (table and column names) are never parameterizable, so any ORM path that interpolates a user-chosen identifier is a sink regardless of binding.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more