CVE-2026-6991 | colinhacks Zod up to 4.3.6 CUID Data Type regexes.ts sql injection (EUVD-2026-25667)
A vulnerability categorized as critical has been discovered in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Executing a manipulation can lead to sql injection.
This vulnerability is tracked as CVE-2026-6991. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.