Dataease

Sqlbot

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 18.09.2026 14:23:22
  • Zuletzt bearbeitet 22.09.2026 20:43:58

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashb...

  • EPSS -
  • Veröffentlicht 17.09.2026 21:41:45
  • Zuletzt bearbeitet 23.09.2026 17:17:49

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, ...

  • EPSS -
  • Veröffentlicht 17.09.2026 21:40:48
  • Zuletzt bearbeitet 23.09.2026 17:17:49

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the SVG without s...

  • EPSS -
  • Veröffentlicht 17.09.2026 21:39:44
  • Zuletzt bearbeitet 23.09.2026 17:17:49

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value int...

  • EPSS -
  • Veröffentlicht 17.09.2026 21:38:37
  • Zuletzt bearbeitet 23.09.2026 17:17:49

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when sel...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 10.08.2026 20:06:32
  • Zuletzt bearbeitet 23.09.2026 17:17:41

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 13.05.2026 21:26:27
  • Zuletzt bearbeitet 15.05.2026 17:34:17

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSch...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 05.05.2026 20:16:36
  • Zuletzt bearbeitet 24.07.2026 23:10:00

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the L...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 02.04.2026 18:15:11
  • Zuletzt bearbeitet 24.07.2026 20:10:00

A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. This manipulation of the argument address causes serve...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 20.03.2026 04:14:45
  • Zuletzt bearbeitet 23.03.2026 18:04:30

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowi...