Dataease

Sqlbot

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.17%
  • Veröffentlicht 20.03.2026 04:14:45
  • Zuletzt bearbeitet 23.03.2026 18:04:30

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowi...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.03.2026 04:08:43
  • Zuletzt bearbeitet 23.03.2026 17:35:16

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 19.03.2026 20:55:51
  • Zuletzt bearbeitet 23.03.2026 17:34:55

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any auth...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 03.03.2026 09:32:06
  • Zuletzt bearbeitet 05.03.2026 21:52:08

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of ...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 02.03.2026 06:16:35
  • Zuletzt bearbeitet 05.03.2026 01:22:53

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to lau...