A vulnerability has been found in Hypequery up to 2.0.1 and classified as critical. Impacted is the function
escapeValue of the file packages/clickhouse/src/core/utils.ts. This manipulation causes injection.
This vulnerability is tracked as CVE-2026-54658. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.