External risk intelligence

Marten SQL Injection via Unescaped String Literals

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-75513

Marten is a .NET library for database interaction used within application code. While it handles data, it is a developer-facing component integrated into backend services, not a standalone internet-facing service or appliance. Exposure relies entirely on the custom implementation of the host application, making direct public internet reachability of this specific component uncommon.

SQL Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Marten, a .NET database and event store, by allowing attackers to potentially bypass authorization and exfiltrate data through crafted SQL inputs. While the direct exposure of Marten to the public internet is unlikely due to its nature as a developer library, the impact depends heavily on how it's integrated into applications.

  • Malicious SQL injection possible in database queries.
  • Protects sensitive data and access controls.
  • Confirm relevance; assess application-level risk.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input to an application using a vulnerable version of Marten. If the application processes this input, it could lead to SQL injection, allowing the attacker to bypass filters, break tenant isolation, or exfiltrate data.

  • Requires authenticated access to the application.
  • Triggered by specific LINQ queries or tenant management operations.
  • Risk of unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, affected Marten document database and event store deployments could allow an attacker to bypass authorization and exfiltrate data through SQL injection. This could also lead to data modification when semicolon-batched Npgsql statements are permitted.

  • Affected: Document database and event store data.
  • Exposure: SQL injection via interpolated strings.
  • Consequence: Authorization bypass and data exfiltration.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application and platform teams are likely responsible for addressing this vulnerability in Marten, a .NET library used for database interactions. The first practical step is to identify all applications that utilize Marten versions 7.0.0 through 9.13.0, determine their business criticality, and confirm their network exposure. Subsequently, accountable owners should be identified to plan remediation, considering factors like maintenance windows and potential vendor coordination for updates.

  • Application owners should own the issue.
  • Verify Marten usage and network reachability.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Marten and how is it used in .NET development?

Marten is a library for .NET applications that allows developers to treat a PostgreSQL database as a document store and event store. It enables complex data querying and management directly from C# code. Engineers use it to simplify interactions with PostgreSQL, effectively mapping object-oriented data structures to database tables, which is essential for building modern transactional and event-driven software architectures.

How does CVE-2026-75513 cause a security weakness?

This CVE involves SQL Injection, classified as CWE-89. The vulnerability occurs because Marten sometimes inserts user-provided input directly into SQL commands without proper security cleaning. Because the library fails to treat this input as a variable, an attacker can use special characters to 'break out' of the intended data field, allowing them to manipulate the resulting database query to perform unauthorized actions.

What actions trigger this Marten vulnerability?

Exploitation generally requires an attacker to provide input that the application subsequently processes through specific LINQ queries or tenant-management operations. For example, using a dictionary indexer key in a filter can trigger the bug. Notably, if your application uses System.Text.Json rather than Newtonsoft for specific dictionary operations, those specific paths remain protected from that particular trigger.

Is my application at risk according to Halo Surface Signal?

Because Marten is an internal developer library rather than a public-facing service, Halo Surface Signal labels direct internet exposure as unlikely. The actual risk depends entirely on your specific application; if your code allows untrusted users to influence inputs processed by Marten's LINQ queries, your application could become a conduit for this issue, even if the library itself is not directly reachable from the web.

How do I start addressing this vulnerability?

The most effective first step is to audit your software inventory to identify which applications include Marten versions between 7.0.0 and 9.13.0. Once identified, prioritize these applications based on their data sensitivity and the type of user input they handle. The vulnerability is resolved in version 9.13.0, so planning an update for those specific library dependencies is the standard path to remediation.

References