Marten 9.13.0
Security release. Fixes SQL injection in the LINQ provider via unescaped string literals (#4911).
Several LINQ / tenant-management code paths interpolated a runtime, potentially attacker-influenced value into generated SQL as a single-quoted literal without escaping or parameterization; a value containing a single quote could break out and inject SQL. The primary vector — a Dictionary<,> indexer key in a Where filter — was reported privately with an executed proof-of-concept (filter / multi-tenant authorization bypass, blind exfiltration).
Fixed sinks:
DictionaryItemMember— dictionary indexer keyDictionaryContainsKeyFilter—ContainsKeykey (Newtonsoft serializer + Enum branch)SelectParser— constant string projected viaSelect(...)DeleteAllForTenant— tenant id in per-tenant projection teardown (now parameterized)DatabaseScopedTenantPartitions— tenant id in partition DDLEventLoader— per-tenant partition-pruning literal (defense-in-depth)
All 9.x users should upgrade. The 8.x line is fixed in 8.37.4. See advisory GHSA-rfx3-98h7-v3xp.