SQL Injection Is Still a Thing: Blocking It in Grant Strings
The mongreldb-php client validates every permission string against a strict allowlist before it builds a GRANT statement, because DDL fragments cannot be bound as parameters and the classic prepared-statement advice does not cover them.