CVE-2026-93660
- EPSS 0.24%
- Veröffentlicht 18.09.2026 14:23:22
- Zuletzt bearbeitet 22.09.2026 20:43:58
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashb...
CVE-2026-53557
- EPSS -
- Veröffentlicht 17.09.2026 21:41:45
- Zuletzt bearbeitet 23.09.2026 17:17:49
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, ...
CVE-2026-53555
- EPSS -
- Veröffentlicht 17.09.2026 21:40:48
- Zuletzt bearbeitet 23.09.2026 17:17:49
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the SVG without s...
- EPSS -
- Veröffentlicht 17.09.2026 21:39:44
- Zuletzt bearbeitet 23.09.2026 17:17:49
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value int...
CVE-2026-53554
- EPSS -
- Veröffentlicht 17.09.2026 21:38:37
- Zuletzt bearbeitet 23.09.2026 17:17:49
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when sel...
CVE-2026-72743
- EPSS 0.17%
- Veröffentlicht 10.08.2026 20:06:32
- Zuletzt bearbeitet 23.09.2026 17:17:41
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content...
CVE-2026-42463
- EPSS 0.25%
- Veröffentlicht 13.05.2026 21:26:27
- Zuletzt bearbeitet 15.05.2026 17:34:17
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSch...
CVE-2026-33324
- EPSS 0.6%
- Veröffentlicht 05.05.2026 20:16:36
- Zuletzt bearbeitet 24.07.2026 23:10:00
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the L...
CVE-2026-5417
- EPSS 0.22%
- Veröffentlicht 02.04.2026 18:15:11
- Zuletzt bearbeitet 24.07.2026 20:10:00
A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. This manipulation of the argument address causes serve...
CVE-2026-32950
- EPSS 0.88%
- Veröffentlicht 20.03.2026 04:14:45
- Zuletzt bearbeitet 23.03.2026 18:04:30
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowi...