๐Ÿ” CVE Alert

CVE-2026-53556

UNKNOWN 0.0

SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can configure a datasource for SQLBot's internal PostgreSQL service and submit a crafted table_name that remains a SELECT operation under the read-only policy while invoking pg_read_file(), pg_read_binary_file(), or pg_ls_dir(). In the default tested trusted loopback authentication configuration, the internal connection accepts invalid credentials and executes with PostgreSQL superuser privileges, allowing filesystem content such as /etc/hosts and /etc/passwd to be returned in the previewData API response and potentially exposing configuration, credentials, authentication secrets, and source code. This issue is fixed in version 1.9.0.

CWE CWE-89
Vendor dataease
Product sqlbot
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for dataease sqlbot

Be the first to know when new unknown vulnerabilities affecting dataease sqlbot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

dataease / SQLBot
< 1.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dataease/SQLBot/security/advisories/GHSA-vwjq-5h4h-x8g5 github.com: https://github.com/dataease/SQLBot/pull/1156 github.com: https://github.com/dataease/SQLBot/commit/76b5176b0e394740fd07c0d1769c0c792e8cb3b4 github.com: https://github.com/dataease/SQLBot/releases/tag/v1.9.0