DuckDB <=0.9.2 and DuckDB extension-template <=0.9.2 are vulnerable to malicious extension injection via the custom extension feature. https://github.com/Tu0Laj1/database_test
Created python-sqlglot tracking bugs for this issue: Affects: fedora-all [bug 2261876]