SQL injection has been one of the most common and dangerous web application vulnerabilities for decades. It occurs when user input gets incorporated directly into SQL queries without proper sanitization, allowing attackers to manipulate the query's behavior.
The classic example goes like this: a login form builds a query like SELECT * FROM users WHERE username = '[input]' AND password = '[input]'. If the application doesn't sanitize inputs, an attacker can enter something like ' OR '1'='1 and bypass authentication entirely.
SQL injection is catalogued as CWE-89 and remains a perennial entry in the OWASP Top 10.
Why It Persists
SQL injection should be a solved problem: we've known how to prevent it for years, yet it remains in the OWASP Top 10 because developers (and now AI agents) keep making the same mistakes.
The fundamental issue is one of convenience. String concatenation is the easiest way to build dynamic queries, and it's what comes naturally when writing code quickly. The more difficult, but correct, method is to use parameterized queries. This method, however, requires a bit more thought and boilerplate, so it's often skipped when developers are under time pressure.
Prevention
Parameterized queries, also called prepared statements, are implemented as follows: instead of concatenating user input into the query string, it is passed as a separate parameter that the database engine treats as data, not code. The OWASP SQL Injection Prevention Cheat Sheet provides detailed guidance on how to do this.
Most modern ORMs and query builders handle this automatically if they're used correctly. However, the danger presents when developers bypass the ORM for performance or flexibility.
AI-Generated SQL
This is a pattern worth watching in AI-generated code. When asked to query a database, AI agents often generate the straightforward string-concatenation approach. It seems to work, and the vulnerability ships.
Security guardrails that specifically check for parameterized query usage can catch these issues before they become problems. That's why Corridor includes SQL injection as a default check. It's a known area where AI-generated code needs guidance, and Corridor helps to prevent it.