A vulnerability has been found in Hypequery up to 2.0.1 and classified as critical. Impacted is the function escapeValue of the file packages/clickhouse/src/core/utils.ts. This manipulation causes injection.

This vulnerability is tracked as CVE-2026-54658. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.