CVE-2026-32950
- EPSS 0.17%
- Veröffentlicht 20.03.2026 04:14:45
- Zuletzt bearbeitet 23.03.2026 18:04:30
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowi...
CVE-2026-32949
- EPSS 0.04%
- Veröffentlicht 20.03.2026 04:08:43
- Zuletzt bearbeitet 23.03.2026 17:35:16
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the...
CVE-2026-32622
- EPSS 0.56%
- Veröffentlicht 19.03.2026 20:55:51
- Zuletzt bearbeitet 23.03.2026 17:34:55
SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any auth...
CVE-2025-15598
- EPSS 0.02%
- Veröffentlicht 03.03.2026 09:32:06
- Zuletzt bearbeitet 05.03.2026 21:52:08
A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of ...
CVE-2025-15597
- EPSS 0.07%
- Veröffentlicht 02.03.2026 06:16:35
- Zuletzt bearbeitet 05.03.2026 01:22:53
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to lau...